2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24921 | HIGH | 7.5 | 3.2% | Mar 5, 2022 | regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression. |
| CVE-2022-25465 | HIGH | 7.8 | 0.7% | Mar 5, 2022 | Espruino 2v11 release was discovered to contain a stack buffer overflow via src/jsvar.c in jsvGetNextSibling. |
| CVE-2022-25044 | HIGH | 7.8 | 0.9% | Mar 5, 2022 | Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString. |
| CVE-2022-23915 | HIGH | 8.8 | 2.9% | Mar 4, 2022 | The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when u... |
| CVE-2022-23233 | HIGH | 7.5 | 0.9% | Mar 4, 2022 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when succe... |
| CVE-2022-25623 | HIGH | 7.8 | 0.3% | Mar 4, 2022 | The Symantec Management Agent is susceptible to a privilege escalation vulnerability. A low privilege local account can ... |
| CVE-2022-21828 | HIGH | 7.2 | 3.7% | Mar 4, 2022 | A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connec... |
| CVE-2022-23729 | HIGH | 7.8 | 0.1% | Mar 4, 2022 | When the device is in factory state, it can be access the shell without adb authentication process. The LG ID is LVE-SMP... |
| CVE-2022-23328 | HIGH | 7.5 | 1.8% | Mar 4, 2022 | A design flaw in all versions of Go-Ethereum allows an attacker node to send 5120 pending transactions of a high gas pri... |
| CVE-2022-23327 | HIGH | 7.5 | 1.8% | Mar 4, 2022 | A design flaw in Go-Ethereum 1.10.12 and older versions allows an attacker node to send 5120 future transactions with a ... |
| CVE-2022-21716 | HIGH | 7.5 | 3.6% | Mar 3, 2022 | Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH clie... |
| CVE-2022-0492 | HIGH | 7.8 | 5.5% | Mar 3, 2022 | A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th... |
| CVE-2022-26129 | HIGH | 7.8 | 1.0% | Mar 3, 2022 | Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the subtlv length in the functio... |
| CVE-2022-26128 | HIGH | 7.8 | 1.0% | Mar 3, 2022 | A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to a wrong check on the input packet length in the... |
| CVE-2022-26127 | HIGH | 7.8 | 1.0% | Mar 3, 2022 | A buffer overflow vulnerability exists in FRRouting through 8.1.0 due to missing a check on the input packet length in t... |
| CVE-2022-26126 | HIGH | 7.8 | 1.1% | Mar 3, 2022 | Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated bin... |
| CVE-2022-26125 | HIGH | 7.8 | 1.0% | Mar 3, 2022 | Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to wrong checks on the input packet length in isisd... |
| CVE-2022-25031 | HIGH | 7.8 | 0.2% | Mar 3, 2022 | Remote Desktop Commander Suite Agent before v4.8 contains an unquoted service path which allows attackers to escalate pr... |
| CVE-2022-22706 | HIGH | 7.8 | 1.2% | Mar 3, 2022 | Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects ... |
| CVE-2022-23648 | HIGH | 7.5 | 27.4% | Mar 3, 2022 | containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to ve... |
| CVE-2022-0528 | HIGH | 7.5 | 1.0% | Mar 3, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository transloadit/uppy prior to 3.3.1. |
| CVE-2022-25471 | HIGH | 8.1 | 0.8% | Mar 3, 2022 | An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access an... |
| CVE-2022-22909 | HIGH | 8.8 | 45.4% | Mar 3, 2022 | HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attack... |
| CVE-2022-25393 | HIGH | 7.5 | 1.2% | Mar 2, 2022 | Simple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter. |
| CVE-2022-25115 | HIGH | 7.8 | 1.5% | Mar 2, 2022 | A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners C... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now