2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27052 | HIGH | 7.8 | 0.3% | Mar 31, 2022 | FreeFtpd version 1.0.13 and below contains an unquoted service path vulnerability which allows local users to launch pro... |
| CVE-2022-27050 | HIGH | 7.8 | 0.3% | Mar 31, 2022 | BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers... |
| CVE-2022-24798 | HIGH | 7.5 | 1.4% | Mar 31, 2022 | Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. IRRd di... |
| CVE-2022-24758 | HIGH | 7.5 | 1.1% | Mar 31, 2022 | The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized... |
| CVE-2022-1176 | HIGH | 7.5 | 1.2% | Mar 31, 2022 | Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96. |
| CVE-2022-25915 | HIGH | 8.8 | 0.4% | Mar 31, 2022 | Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmwa... |
| CVE-2022-1191 | HIGH | 8.1 | 0.9% | Mar 31, 2022 | SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96. |
| CVE-2022-28128 | HIGH | 7.8 | 0.4% | Mar 31, 2022 | Untrusted search path vulnerability in AttacheCase ver.3.6.1.0 and earlier allows an attacker to gain privileges and exe... |
| CVE-2022-26019 | HIGH | 8.8 | 4.2% | Mar 31, 2022 | Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pf... |
| CVE-2022-25348 | HIGH | 7.8 | 0.4% | Mar 31, 2022 | Untrusted search path vulnerability in AttacheCase ver.4.0.2.7 and earlier allows an attacker to gain privileges and exe... |
| CVE-2022-24299 | HIGH | 8.8 | 1.9% | Mar 31, 2022 | Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and ... |
| CVE-2022-22986 | HIGH | 8.8 | 0.7% | Mar 31, 2022 | Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier... |
| CVE-2022-25008 | HIGH | 8.8 | 4.3% | Mar 30, 2022 | totolink EX300_v2 V4.0.3c.140_B20210429 and EX1200T V4.1.2cu.5230_B20210706 does not contain an authentication mechanism... |
| CVE-2022-24790 | HIGH | 7.5 | 2.1% | Mar 30, 2022 | Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a pr... |
| CVE-2022-24763 | HIGH | 7.5 | 2.0% | Mar 30, 2022 | PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior cont... |
| CVE-2022-1160 | HIGH | 7.8 | 1.3% | Mar 30, 2022 | heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647. |
| CVE-2022-28223 | HIGH | 7.2 | 1.0% | Mar 30, 2022 | Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a mal... |
| CVE-2022-27772 | HIGH | 7.8 | 0.6% | Mar 30, 2022 | spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerabilit... |
| CVE-2022-24132 | HIGH | 7.5 | 1.1% | Mar 30, 2022 | phpshe V1.8 is affected by a denial of service (DoS) attack in the registry's verification code, which can paralyze the ... |
| CVE-2022-22772 | HIGH | 7.5 | 2.2% | Mar 30, 2022 | The cfsend, cfrecv, and CyberResp components of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for UN... |
| CVE-2022-23793 | HIGH | 7.5 | 2.0% | Mar 30, 2022 | An issue was discovered in Joomla! 3.0.0 through 3.10.6 & 4.0.0 through 4.1.0. Extracting an specifilcy crafted tar pack... |
| CVE-2022-22996 | HIGH | 7.8 | 0.3% | Mar 30, 2022 | The G-RAID 4/8 Software Utility setups for Windows were affected by a DLL hijacking vulnerability. Successful exploitati... |
| CVE-2022-20002 | HIGH | 7.8 | 0.1% | Mar 30, 2022 | In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to l... |
| CVE-2022-0998 | HIGH | 7.8 | 0.4% | Mar 30, 2022 | An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_... |
| CVE-2022-1155 | HIGH | 7.4 | 1.0% | Mar 30, 2022 | Old sessions are not blocked by the login enable function. in GitHub repository snipe/snipe-it prior to 5.3.10. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now