2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-28391HIGH8.8BusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's ...
CVE-2022-28390HIGH7.8ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.
CVE-2022-28380HIGH7.5The rc-httpd component through 2022-03-31 for 9front (Plan 9 fork) allows ..%2f directory traversal if serve-static is u...
CVE-2022-0088HIGH7.4Cross-Site Request Forgery (CSRF) in GitHub repository yourls/yourls prior to 1.8.3.
CVE-2022-28376HIGH8.1Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a...
CVE-2022-28355HIGH7.5randomUUID in Scala.js before 1.10.0 generates predictable values.
CVE-2022-26419HIGH7.8Omron CX-Position (versions 2.5.3 and prior) is vulnerable to multiple stack-based buffer overflow conditions while pars...
CVE-2022-26417HIGH7.8Omron CX-Position (versions 2.5.3 and prior) is vulnerable to a use after free memory condition while processing a speci...
CVE-2022-26022HIGH7.8Omron CX-Position (versions 2.5.3 and prior) is vulnerable to an out-of-bounds write while processing a specific project...
CVE-2022-25959HIGH7.8Omron CX-Position (versions 2.5.3 and prior) is vulnerable to memory corruption while processing a specific project file...
CVE-2022-25159HIGH8.1Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions...
CVE-2022-25156HIGH8.1Use of Weak Hash vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric M...
CVE-2022-25155HIGH8.1Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U...
CVE-2022-1159HIGH7.2Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator...
CVE-2022-1098HIGH7.8Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combin...
CVE-2022-1068HIGH7.5Modbus Tools Modbus Slave (versions 7.4.2 and prior) is vulnerable to a stack-based buffer overflow in the registration ...
CVE-2022-0741HIGH7.5Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal env...
CVE-2022-0425HIGH7.6A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 all...
CVE-2022-24426HIGH7.8Dell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerabili...
CVE-2022-23155HIGH7.2Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious use...
CVE-2022-22332HIGH7.5IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocat...
CVE-2022-22331HIGH7.1IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information...
CVE-2022-22327HIGH7.5IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could ...
CVE-2022-21947HIGH8.8A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to...
CVE-2022-25017HIGH8.8Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now