2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-20767HIGH7.5A vulnerability in the Snort rule evaluation function of Cisco Firepower Threat Defense (FTD) Software could allow an un...
CVE-2022-20760HIGH7.5A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat D...
CVE-2022-20759HIGH8.8A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) ...
CVE-2022-20757HIGH7.5A vulnerability in the connection handling function in Cisco Firepower Threat Defense (FTD) Software could allow an unau...
CVE-2022-20751HIGH7.5A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD) Software could allow ...
CVE-2022-20746HIGH7.5A vulnerability in the TCP proxy functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthent...
CVE-2022-20745HIGH7.5A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) ...
CVE-2022-20743HIGH8.8A vulnerability in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authe...
CVE-2022-20742HIGH7.4A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat D...
CVE-2022-20737HIGH7.1A vulnerability in the handler for HTTP authentication for resources accessed through the Clientless SSL VPN portal of C...
CVE-2022-20730HIGH7.5A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow a...
CVE-2022-20729HIGH7.8A vulnerability in CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to ...
CVE-2022-20715HIGH8.6A vulnerability in the remote access SSL VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Fire...
CVE-2022-24897HIGH7.5APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2....
CVE-2022-23723HIGH7.7An MFA bypass vulnerability exists in the PingFederate PingOne MFA Integration Kit when adapter HTML templates are used ...
CVE-2022-28613HIGH7.5A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus T...
CVE-2022-1273HIGH7.2The Import WP WordPress plugin before 2.4.6 does not validate the imported file in some cases, allowing high privilege u...
CVE-2022-1239HIGH8.8The HubSpot WordPress plugin before 8.8.15 does not validate the proxy URL given to the proxy REST endpoint, which could...
CVE-2022-0952HIGH8.8The Sitemap by click5 WordPress plugin before 1.0.36 does not have authorisation and CSRF checks when updating options v...
CVE-2022-27983HIGH7.5RG-NBR-E Enterprise Gateway RG-NBR2100G-E was discovered to contain an arbitrary file read vulnerability via the url par...
CVE-2022-28572HIGH8.8Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability in `SetIPv6Status` function
CVE-2022-23064HIGH8.8In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host ...
CVE-2022-23904HIGH8Rainworx Auctionworx < 3.1R2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack that allows an authenticated us...
CVE-2022-29970HIGH7.5Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
CVE-2022-29968HIGH7.8An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kio...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now