2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-26642HIGH7.2TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the X_TP_ClonedMACAddress parameter.
CVE-2022-26641HIGH7.2TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the httpRemotePort parameter.
CVE-2022-26640HIGH7.2TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the minAddress parameter.
CVE-2022-26639HIGH7.2TP-LINK TL-WR840N(ES)_V6.20 was discovered to contain a buffer overflow via the DNSServers parameter.
CVE-2022-24789HIGH7.6C1 CMS is an open-source, .NET based Content Management System (CMS). Versions prior to 6.12 allow an authenticated user...
CVE-2022-27658HIGH7.5Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could ...
CVE-2022-0751HIGH8.8Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to ...
CVE-2022-0738HIGH7.5An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting fr...
CVE-2022-0427HIGH8.8Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows a...
CVE-2022-0136HIGH8.1A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnera...
CVE-2022-0770HIGH8.8The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write ...
CVE-2022-0499HIGH8.8The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and ...
CVE-2022-26271HIGH7.574cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controlle...
CVE-2022-26259HIGH7.8A buffer over flow in Xiongmai DVR devices NBD80X16S-KL, NBD80X09S-KL, NBD80X08S-KL, NBD80X09RA-KL, AHB80X04R-MH, AHB80X...
CVE-2022-27947HIGH8.8NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via she...
CVE-2022-27946HIGH8.8NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via she...
CVE-2022-27945HIGH8.8NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via she...
CVE-2022-27942HIGH7.8tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c.
CVE-2022-27941HIGH7.8tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c.
CVE-2022-27940HIGH7.8tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c.
CVE-2022-1071HIGH8.2User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2.
CVE-2022-26659HIGH7.1Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable ...
CVE-2022-25523HIGH8.8TypesetterCMS v5.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which is exploited via a crafted POST r...
CVE-2022-1049HIGH8.8A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts w...
CVE-2022-0995HIGH7.8An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now