2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20679 | HIGH | 7.7 | 1.2% | Apr 15, 2022 | A vulnerability in the IPSec decryption routine of Cisco IOS XE Software could allow an unauthenticated, remote attacker... |
| CVE-2022-20678 | HIGH | 7.5 | 0.9% | Apr 15, 2022 | A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cau... |
| CVE-2022-20622 | HIGH | 7.5 | 1.3% | Apr 15, 2022 | A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points So... |
| CVE-2022-28048 | HIGH | 8.8 | 1.5% | Apr 15, 2022 | STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac. |
| CVE-2022-28042 | HIGH | 8.8 | 1.5% | Apr 15, 2022 | stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode. |
| CVE-2022-27474 | HIGH | 7.2 | 22.5% | Apr 15, 2022 | SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text f... |
| CVE-2022-28345 | HIGH | 7.5 | 2.1% | Apr 15, 2022 | The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs begi... |
| CVE-2022-26498 | HIGH | 7.5 | 15.5% | Apr 15, 2022 | An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not ... |
| CVE-2022-27188 | HIGH | 7.8 | 0.5% | Apr 15, 2022 | OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTU... |
| CVE-2022-24854 | HIGH | 8.8 | 1.0% | Apr 14, 2022 | Metabase is an open source business intelligence and analytics application. SQLite has an FDW-like feature called `ATTAC... |
| CVE-2022-24846 | HIGH | 7.2 | 1.2% | Apr 14, 2022 | GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked ... |
| CVE-2022-22966 | HIGH | 7.2 | 6.3% | Apr 14, 2022 | An authenticated, high privileged malicious actor with network access to the VMware Cloud Director tenant or provider ma... |
| CVE-2022-1304 | HIGH | 7.8 | 1.3% | Apr 14, 2022 | An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and po... |
| CVE-2022-22149 | HIGH | 8.8 | 71.3% | Apr 14, 2022 | A SQL injection vulnerability exists in the HelpdeskEmailActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A... |
| CVE-2022-21234 | HIGH | 8.8 | 71.3% | Apr 14, 2022 | An SQL injection vulnerability exists in the EchoAssets.aspx functionality of Lansweeper lansweeper 9.1.20.2. A speciall... |
| CVE-2022-21210 | HIGH | 8.8 | 69.8% | Apr 14, 2022 | An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specia... |
| CVE-2022-21154 | HIGH | 7.8 | 1.0% | Apr 14, 2022 | An integer overflow vulnerability exists in the fltSaveCMP functionality of Leadtools 22. A specially-crafted BMP file c... |
| CVE-2022-25165 | HIGH | 7 | 0.5% | Apr 14, 2022 | An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN conf... |
| CVE-2022-22198 | HIGH | 7.5 | 0.9% | Apr 14, 2022 | An Access of Uninitialized Pointer vulnerability in the SIP ALG of Juniper Networks Junos OS allows an unauthenticated n... |
| CVE-2022-22197 | HIGH | 7.5 | 1.0% | Apr 14, 2022 | An Operation on a Resource after Expiration or Release vulnerability in the Routing Protocol Daemon (RPD) of Juniper Net... |
| CVE-2022-22195 | HIGH | 7.5 | 1.0% | Apr 14, 2022 | An Improper Update of Reference Count vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthe... |
| CVE-2022-22194 | HIGH | 7.5 | 0.9% | Apr 14, 2022 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the packetIO daemon of Juniper Networks Junos O... |
| CVE-2022-22190 | HIGH | 7.5 | 0.9% | Apr 14, 2022 | An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unaut... |
| CVE-2022-22189 | HIGH | 7.8 | 0.2% | Apr 14, 2022 | An Incorrect Ownership Assignment vulnerability in Juniper Networks Contrail Service Orchestration (CSO) allows a locall... |
| CVE-2022-22188 | HIGH | 7.5 | 1.5% | Apr 14, 2022 | An Uncontrolled Memory Allocation vulnerability leading to a Heap-based Buffer Overflow in the packet forwarding engine ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now