2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-44938CRITICAL9.8Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brut...
CVE-2022-41717MEDIUM5.3An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contai...
CVE-2022-4366HIGH7.5Missing Authorization in GitHub repository lirantal/daloradius prior to master branch.
CVE-2022-46831MEDIUM4.9In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allo...
CVE-2022-46830MEDIUM5.3In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
CVE-2022-46829HIGH8.8In JetBrains JetBrains Gateway before 2022.3 a client could connect without a valid token if the host consented.
CVE-2022-46828HIGH7.8In JetBrains IntelliJ IDEA before 2022.3 a DYLIB injection on macOS was possible.
CVE-2022-46827MEDIUM5.5In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was po...
CVE-2022-46826MEDIUM5.5In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a pa...
CVE-2022-46825LOW3.3In JetBrains IntelliJ IDEA before 2022.3 the built-in web server leaked information about open projects.
CVE-2022-46824HIGH7.8In JetBrains IntelliJ IDEA before 2022.2.4 a buffer overflow in the fsnotifier daemon on macOS was possible.
CVE-2022-40939MEDIUM4.9In certain Secustation products the administrator account password can be read. This affects V2.5.5.3116-S50-SMA-B201711...
CVE-2022-38599MEDIUM6.5Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user...
CVE-2022-4123LOW3.3A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path ...
CVE-2022-4122MEDIUM5.3A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore r...
CVE-2022-45877MEDIUM5.3OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text dur...
CVE-2022-45525HIGH7.5Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the downaction parameter at /goform/CertListInf...
CVE-2022-45524HIGH7.5Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the opttype parameter at /goform/IPSECsave.
CVE-2022-45523HIGH7.5Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/L7Im.
CVE-2022-45522HIGH7.5Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeClientFilter.
CVE-2022-45521HIGH7.5Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SafeUrlFilter.
CVE-2022-45520HIGH7.5Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/qossetting.
CVE-2022-45519HIGH7.5Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the Go parameter at /goform/SafeMacFilter.
CVE-2022-45518HIGH7.5Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/SetIpBind.
CVE-2022-45517HIGH7.5Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the page parameter at /goform/VirtualSer.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now