2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28391 | HIGH | 8.8 | 3.5% | Apr 3, 2022 | BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's ... |
| CVE-2022-28390 | HIGH | 7.8 | 0.4% | Apr 3, 2022 | ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free. |
| CVE-2022-28380 | HIGH | 7.5 | 1.5% | Apr 3, 2022 | The rc-httpd component through 2022-03-31 for 9front (Plan 9 fork) allows ..%2f directory traversal if serve-static is u... |
| CVE-2022-0088 | HIGH | 7.4 | 2.0% | Apr 3, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3. |
| CVE-2022-28376 | HIGH | 8.1 | 1.2% | Apr 3, 2022 | Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a... |
| CVE-2022-28355 | HIGH | 7.5 | 1.4% | Apr 2, 2022 | randomUUID in Scala.js before 1.10.0 generates predictable values. |
| CVE-2022-26419 | HIGH | 7.8 | 2.0% | Apr 1, 2022 | Omron CX-Position (versions 2.5.3 and prior) is vulnerable to multiple stack-based buffer overflow conditions while pars... |
| CVE-2022-26417 | HIGH | 7.8 | 1.4% | Apr 1, 2022 | Omron CX-Position (versions 2.5.3 and prior) is vulnerable to a use after free memory condition while processing a speci... |
| CVE-2022-26022 | HIGH | 7.8 | 1.4% | Apr 1, 2022 | Omron CX-Position (versions 2.5.3 and prior) is vulnerable to an out-of-bounds write while processing a specific project... |
| CVE-2022-25959 | HIGH | 7.8 | 1.4% | Apr 1, 2022 | Omron CX-Position (versions 2.5.3 and prior) is vulnerable to memory corruption while processing a specific project file... |
| CVE-2022-25159 | HIGH | 8.1 | 2.1% | Apr 1, 2022 | Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions... |
| CVE-2022-25156 | HIGH | 8.1 | 1.2% | Apr 1, 2022 | Use of Weak Hash vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric M... |
| CVE-2022-25155 | HIGH | 8.1 | 2.1% | Apr 1, 2022 | Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U... |
| CVE-2022-1159 | HIGH | 7.2 | 3.4% | Apr 1, 2022 | Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator... |
| CVE-2022-1098 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combin... |
| CVE-2022-1068 | HIGH | 7.5 | 0.9% | Apr 1, 2022 | Modbus Tools Modbus Slave (versions 7.4.2 and prior) is vulnerable to a stack-based buffer overflow in the registration ... |
| CVE-2022-0741 | HIGH | 7.5 | 1.4% | Apr 1, 2022 | Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal env... |
| CVE-2022-0425 | HIGH | 7.6 | 0.6% | Apr 1, 2022 | A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 all... |
| CVE-2022-24426 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Dell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerabili... |
| CVE-2022-23155 | HIGH | 7.2 | 1.3% | Apr 1, 2022 | Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious use... |
| CVE-2022-22332 | HIGH | 7.5 | 0.7% | Apr 1, 2022 | IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocat... |
| CVE-2022-22331 | HIGH | 7.1 | 0.7% | Apr 1, 2022 | IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information... |
| CVE-2022-22327 | HIGH | 7.5 | 0.7% | Apr 1, 2022 | IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could ... |
| CVE-2022-21947 | HIGH | 8.8 | 0.6% | Apr 1, 2022 | A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to... |
| CVE-2022-25017 | HIGH | 8.8 | 29.1% | Apr 1, 2022 | Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now