2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36585CRITICAL9.8In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused ...
CVE-2022-36089CRITICAL9.8KubeVela is an application delivery platform Users using KubeVela's VelaUX APIServer could be affected by an authenticat...
CVE-2022-36088MEDIUM5.5GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to ...
CVE-2022-36086CRITICAL9.8linked_list_allocator is an allocator usable for no_std systems. Prior to version 0.10.2, the heap initialization method...
CVE-2022-38254MEDIUM6.1Nagios XI before v5.8.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the ajax.php script in ...
CVE-2022-38251MEDIUM4.8Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Performance Setting...
CVE-2022-38250CRITICAL9.8Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs p...
CVE-2022-38249MEDIUM6.1Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the MTR component in version 1...
CVE-2022-38248MEDIUM6.1Nagios XI before v5.8.7 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at auditlog.php.
CVE-2022-38247MEDIUM4.8Nagios XI v5.8.6 was discovered to contain a cross-site scripting (XSS) vulnerability via the System Settings page under...
CVE-2022-36083MEDIUM5.3JOSE is "JSON Web Almost Everything" - JWA, JWS, JWE, JWT, JWK, JWKS with no dependencies using runtime's native crypto ...
CVE-2022-36082MEDIUM5.3mangadex-downloader is a command-line tool to download manga from MangaDex. When using `file:<location>` command and `<l...
CVE-2022-36081HIGH7.5Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, Wikmd is vulnerable to path traversal when access...
CVE-2022-36080MEDIUM6.1Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, an attacker could capture user's session cookies ...
CVE-2022-36079HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Internal fields ...
CVE-2022-36049HIGH7.5Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a K...
CVE-2022-3130CRITICAL9.8A vulnerability classified as critical has been found in codeprojects Online Driving School. This affects an unknown par...
CVE-2022-3129CRITICAL9.8A vulnerability was found in codeprojects Online Driving School. It has been rated as critical. Affected by this issue i...
CVE-2022-36073HIGH8.8RubyGems.org is the Ruby community gem host. A bug in password & email change confirmation code allowed an attacker to c...
CVE-2022-38314CRITICAL9.8Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /go...
CVE-2022-38313CRITICAL9.8Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /go...
CVE-2022-38312CRITICAL9.8Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /go...
CVE-2022-38311CRITICAL9.8Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /go...
CVE-2022-38310CRITICAL9.8Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /go...
CVE-2022-38309CRITICAL9.8Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /go...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now