2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23688 | MEDIUM | 4.3 | 0.3% | Sep 6, 2022 | Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation o... |
| CVE-2022-23687 | MEDIUM | 4.3 | 0.3% | Sep 6, 2022 | Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation o... |
| CVE-2022-23686 | MEDIUM | 4.3 | 0.3% | Sep 6, 2022 | Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation o... |
| CVE-2022-23684 | HIGH | 8.8 | 1.0% | Sep 6, 2022 | A vulnerability in the web-based management interface of AOS-CX could allow a remote authenticated user with read-only p... |
| CVE-2022-23683 | HIGH | 7.2 | 1.6% | Sep 6, 2022 | Authenticated command injection vulnerabilities exist in the AOS-CX Network Analytics Engine via NAE scripts. Successful... |
| CVE-2022-23682 | HIGH | 7.8 | 0.7% | Sep 6, 2022 | Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. ... |
| CVE-2022-23681 | HIGH | 7.8 | 0.6% | Sep 6, 2022 | Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. ... |
| CVE-2022-23680 | HIGH | 8.8 | 0.4% | Sep 6, 2022 | AOS-CX lacks Anti-CSRF protections in place for state-changing operations. This can potentially be exploited by an attac... |
| CVE-2022-23679 | HIGH | 8.8 | 0.4% | Sep 6, 2022 | AOS-CX lacks Anti-CSRF protections in place for state-changing operations. This can potentially be exploited by an attac... |
| CVE-2022-23678 | MEDIUM | 5.9 | 0.8% | Sep 6, 2022 | A vulnerability in the Aruba Virtual Intranet Access (VIA) client for Microsoft Windows operating system client communic... |
| CVE-2022-23451 | HIGH | 8.1 | 1.0% | Sep 6, 2022 | An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any ... |
| CVE-2022-1697 | LOW | 3.9 | 0.2% | Sep 6, 2022 | Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted p... |
| CVE-2022-1628 | MEDIUM | 5.4 | 0.5% | Sep 6, 2022 | The Simple SEO plugin for WordPress is vulnerable to attribute-based stored Cross-Site Scripting in versions up to, and ... |
| CVE-2022-1260 | — | — | — | Sep 6, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-0844 | — | — | — | Sep 6, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-40112 | HIGH | 7.5 | 0.7% | Sep 6, 2022 | TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable Buffer Overflow via the hostname parameter in bin... |
| CVE-2022-40111 | CRITICAL | 9.8 | 0.7% | Sep 6, 2022 | In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware... |
| CVE-2022-40110 | HIGH | 7.5 | 0.7% | Sep 6, 2022 | TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Buffer Overflow via /bin/boa. |
| CVE-2022-40109 | CRITICAL | 9.8 | 0.7% | Sep 6, 2022 | TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa. |
| CVE-2022-37843 | CRITICAL | 9.8 | 1.5% | Sep 6, 2022 | In TOTOLINK A860R V4.1.2cu.5182_B20201027 in cstecgi.cgi, the acquired parameters are directly put into the system for e... |
| CVE-2022-37842 | CRITICAL | 9.8 | 0.8% | Sep 6, 2022 | In TOTOLINK A860R V4.1.2cu.5182_B20201027, the parameters in infostat.cgi are not filtered, causing a buffer overflow vu... |
| CVE-2022-37841 | HIGH | 7.5 | 0.6% | Sep 6, 2022 | In TOTOLINK A860R V4.1.2cu.5182_B20201027 there is a hard coded password for root in /etc/shadow.sample. |
| CVE-2022-37840 | CRITICAL | 9.8 | 0.8% | Sep 6, 2022 | In TOTOLINK A860R V4.1.2cu.5182_B20201027, the main function in downloadfile.cgi has a buffer overflow vulnerability. |
| CVE-2022-37839 | CRITICAL | 9.8 | 0.8% | Sep 6, 2022 | TOTOLINK A860R V4.1.2cu.5182_B20201027 is vulnerable to Buffer Overflow via Cstecgi.cgi. |
| CVE-2022-36584 | CRITICAL | 9.8 | 0.8% | Sep 6, 2022 | In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now