2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0988 | HIGH | 7.5 | 0.5% | Mar 25, 2022 | Delta Electronics DIAEnergie (Version 1.7.5 and prior) is vulnerable to cleartext transmission as the web application ru... |
| CVE-2022-0983 | HIGH | 8.8 | 0.9% | Mar 25, 2022 | An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability ... |
| CVE-2022-0759 | HIGH | 8.1 | 0.9% | Mar 25, 2022 | A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API... |
| CVE-2022-0500 | HIGH | 7.8 | 0.3% | Mar 25, 2022 | A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the... |
| CVE-2022-0435 | HIGH | 8.8 | 68.0% | Mar 25, 2022 | A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with ... |
| CVE-2022-0330 | HIGH | 7.8 | 0.4% | Mar 25, 2022 | A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may r... |
| CVE-2022-27882 | HIGH | 7.5 | 1.9% | Mar 25, 2022 | slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow... |
| CVE-2022-27881 | HIGH | 7.5 | 1.9% | Mar 25, 2022 | engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertis... |
| CVE-2022-24778 | HIGH | 7.5 | 2.7% | Mar 25, 2022 | The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-... |
| CVE-2022-24777 | HIGH | 7.5 | 1.1% | Mar 25, 2022 | grpc-swift is the Swift language implementation of gRPC, a remote procedure call (RPC) framework. Prior to version 1.7.2... |
| CVE-2022-27227 | HIGH | 7.5 | 4.9% | Mar 25, 2022 | In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4... |
| CVE-2022-1064 | HIGH | 8.8 | 1.1% | Mar 25, 2022 | SQL injection through marking blog comments on bulk as spam in GitHub repository forkcms/forkcms prior to 5.11.1. |
| CVE-2022-22688 | HIGH | 8.8 | 1.6% | Mar 25, 2022 | Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functi... |
| CVE-2022-25571 | HIGH | 7.5 | 0.9% | Mar 24, 2022 | Bluedon Information Security Technologies Co.,Ltd Internet Access Detector v1.0 was discovered to contain an information... |
| CVE-2022-24781 | HIGH | 7.1 | 0.9% | Mar 24, 2022 | Geon is a board game based on solving questions about the Pythagorean Theorem. Malicious users can obtain the uuid from ... |
| CVE-2022-25568 | HIGH | 7.5 | 6.8% | Mar 24, 2022 | MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To explo... |
| CVE-2022-0153 | HIGH | 7.5 | 1.1% | Mar 24, 2022 | SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1. |
| CVE-2022-0551 | HIGH | 7.2 | 0.9% | Mar 24, 2022 | Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticat... |
| CVE-2022-0550 | HIGH | 7.2 | 0.9% | Mar 24, 2022 | Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an auth... |
| CVE-2022-1061 | HIGH | 7.5 | 0.9% | Mar 24, 2022 | Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8. |
| CVE-2022-0315 | HIGH | 7.5 | 0.9% | Mar 24, 2022 | Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0. |
| CVE-2022-25268 | HIGH | 8.8 | 0.4% | Mar 23, 2022 | Passwork On-Premise Edition before 4.6.13 allows CSRF via the groups, password, and history subsystems. |
| CVE-2022-25267 | HIGH | 8.8 | 1.4% | Mar 23, 2022 | Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files). |
| CVE-2022-27192 | HIGH | 7.5 | 1.1% | Mar 23, 2022 | The Reporting module in Aseco Lietuva document management system DVS Avilys before 3.5.58 allows unauthorized file downl... |
| CVE-2022-24768 | HIGH | 8.8 | 1.2% | Mar 23, 2022 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All unpatched versions of Argo CD starting wit... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now