2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-20679HIGH7.7A vulnerability in the IPSec decryption routine of Cisco IOS XE Software could allow an unauthenticated, remote attacker...
CVE-2022-20678HIGH7.5A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cau...
CVE-2022-20622HIGH7.5A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points So...
CVE-2022-28048HIGH8.8STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.
CVE-2022-28042HIGH8.8stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.
CVE-2022-27474HIGH7.2SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text f...
CVE-2022-28345HIGH7.5The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs begi...
CVE-2022-26498HIGH7.5An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files that are not ...
CVE-2022-27188HIGH7.8OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTU...
CVE-2022-24854HIGH8.8Metabase is an open source business intelligence and analytics application. SQLite has an FDW-like feature called `ATTAC...
CVE-2022-24846HIGH7.2GeoWebCache is a tile caching server implemented in Java. The GeoWebCache disk quota mechanism can perform an unchecked ...
CVE-2022-22966HIGH7.2An authenticated, high privileged malicious actor with network access to the VMware Cloud Director tenant or provider ma...
CVE-2022-1304HIGH7.8An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and po...
CVE-2022-22149HIGH8.8A SQL injection vulnerability exists in the HelpdeskEmailActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A...
CVE-2022-21234HIGH8.8An SQL injection vulnerability exists in the EchoAssets.aspx functionality of Lansweeper lansweeper 9.1.20.2. A speciall...
CVE-2022-21210HIGH8.8An SQL injection vulnerability exists in the AssetActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specia...
CVE-2022-21154HIGH7.8An integer overflow vulnerability exists in the fltSaveCMP functionality of Leadtools 22. A specially-crafted BMP file c...
CVE-2022-25165HIGH7An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN conf...
CVE-2022-22198HIGH7.5An Access of Uninitialized Pointer vulnerability in the SIP ALG of Juniper Networks Junos OS allows an unauthenticated n...
CVE-2022-22197HIGH7.5An Operation on a Resource after Expiration or Release vulnerability in the Routing Protocol Daemon (RPD) of Juniper Net...
CVE-2022-22195HIGH7.5An Improper Update of Reference Count vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthe...
CVE-2022-22194HIGH7.5An Improper Check for Unusual or Exceptional Conditions vulnerability in the packetIO daemon of Juniper Networks Junos O...
CVE-2022-22190HIGH7.5An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unaut...
CVE-2022-22189HIGH7.8An Incorrect Ownership Assignment vulnerability in Juniper Networks Contrail Service Orchestration (CSO) allows a locall...
CVE-2022-22188HIGH7.5An Uncontrolled Memory Allocation vulnerability leading to a Heap-based Buffer Overflow in the packet forwarding engine ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now