2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-0408HIGH7.8Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-0407HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-24124HIGH7.5The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as d...
CVE-2022-24122HIGH7.8kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-aft...
CVE-2022-21721HIGH7.5Next.js is a React framework. Starting with version 12.0.0 and prior to version 12.0.9, vulnerable code could allow a ba...
CVE-2022-0393HIGH7.1Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
CVE-2022-0392HIGH7.8Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.
CVE-2022-23888HIGH8.8YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component /yzmcms/comment/index/init.ht...
CVE-2022-23727HIGH7.8There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is ab...
CVE-2022-22993HIGH8.8A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to imperson...
CVE-2022-22790HIGH7.5SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at ...
CVE-2022-21801HIGH7.5A denial of service vulnerability exists in the netserver recv_command functionality of reolink RLC-410W v3.0.0.136_2012...
CVE-2022-21796HIGH8.2A memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.13...
CVE-2022-21236HIGH7.5An information disclosure vulnerability exists due to a web server misconfiguration in the Reolink RLC-410W v3.0.0.136_2...
CVE-2022-21134HIGH7.5A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0....
CVE-2022-23098HIGH7.5An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite lo...
CVE-2022-23181HIGH7The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1...
CVE-2022-22828HIGH7.5An insecure direct object reference for the file-download URL in Synametrics SynaMan before 5.0 allows a remote attacker...
CVE-2022-23990HIGH7.5Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
CVE-2022-0368HIGH7.8Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
CVE-2022-0361HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-0359HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-21944HIGH7.8A UNIX Symbolic Link (Symlink) Following vulnerability in the systemd service file for watchman of openSUSE Backports SL...
CVE-2022-23968HIGH7.5Xerox VersaLink devices on specific versions of firmware before 2022-01-26 allow remote attackers to brick the device vi...
CVE-2022-0355HIGH7.5Improper Removal of Sensitive Information Before Storage or Transfer in NPM simple-get prior to 4.0.1.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now