2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0408 | HIGH | 7.8 | 1.5% | Jan 30, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-0407 | HIGH | 7.8 | 1.2% | Jan 30, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-24124 | HIGH | 7.5 | 58.9% | Jan 29, 2022 | The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d... |
| CVE-2022-24122 | HIGH | 7.8 | 1.0% | Jan 29, 2022 | kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-aft... |
| CVE-2022-21721 | HIGH | 7.5 | 2.2% | Jan 28, 2022 | Next.js is a React framework. Starting with version 12.0.0 and prior to version 12.0.9, vulnerable code could allow a ba... |
| CVE-2022-0393 | HIGH | 7.1 | 1.4% | Jan 28, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-0392 | HIGH | 7.8 | 1.5% | Jan 28, 2022 | Heap-based Buffer Overflow in GitHub repository vim prior to 8.2. |
| CVE-2022-23888 | HIGH | 8.8 | 0.8% | Jan 28, 2022 | YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.ht... |
| CVE-2022-23727 | HIGH | 7.8 | 0.2% | Jan 28, 2022 | There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is ab... |
| CVE-2022-22993 | HIGH | 8.8 | 0.8% | Jan 28, 2022 | A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to imperson... |
| CVE-2022-22790 | HIGH | 7.5 | 1.0% | Jan 28, 2022 | SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at ... |
| CVE-2022-21801 | HIGH | 7.5 | 1.1% | Jan 28, 2022 | A denial of service vulnerability exists in the netserver recv_command functionality of reolink RLC-410W v3.0.0.136_2012... |
| CVE-2022-21796 | HIGH | 8.2 | 1.3% | Jan 28, 2022 | A memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.13... |
| CVE-2022-21236 | HIGH | 7.5 | 1.8% | Jan 28, 2022 | An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_2... |
| CVE-2022-21134 | HIGH | 7.5 | 0.9% | Jan 28, 2022 | A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.... |
| CVE-2022-23098 | HIGH | 7.5 | 2.5% | Jan 28, 2022 | An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite lo... |
| CVE-2022-23181 | HIGH | 7 | 0.7% | Jan 27, 2022 | The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1... |
| CVE-2022-22828 | HIGH | 7.5 | 2.1% | Jan 27, 2022 | An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker... |
| CVE-2022-23990 | HIGH | 7.5 | 4.0% | Jan 26, 2022 | Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. |
| CVE-2022-0368 | HIGH | 7.8 | 1.5% | Jan 26, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-0361 | HIGH | 7.8 | 1.6% | Jan 26, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-0359 | HIGH | 7.8 | 1.3% | Jan 26, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-21944 | HIGH | 7.8 | 0.3% | Jan 26, 2022 | A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SL... |
| CVE-2022-23968 | HIGH | 7.5 | 1.9% | Jan 26, 2022 | Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device vi... |
| CVE-2022-0355 | HIGH | 7.5 | 2.0% | Jan 26, 2022 | Improper Removal of Sensitive Information Before Storage or Transfer in NPM simple-get prior to 4.0.1. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now