2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36566 | CRITICAL | 9.8 | 2.1% | Aug 31, 2022 | Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function. |
| CVE-2022-38152 | HIGH | 7.5 | 2.1% | Aug 31, 2022 | An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is cal... |
| CVE-2022-3028 | HIGH | 7 | 0.2% | Aug 31, 2022 | A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple ca... |
| CVE-2022-37122 | HIGH | 7.5 | 18.2% | Aug 31, 2022 | Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 s... |
| CVE-2022-30318 | CRITICAL | 9.8 | 1.3% | Aug 31, 2022 | Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell Cont... |
| CVE-2022-30317 | CRITICAL | 9.1 | 0.7% | Aug 31, 2022 | Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055... |
| CVE-2022-2866 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | FATEK FvDesigner version 1.5.103 and prior is vulnerable to an out-of-bounds write while processing project files. If a ... |
| CVE-2022-2759 | HIGH | 8.6 | 1.0% | Aug 31, 2022 | Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions w... |
| CVE-2022-2758 | MEDIUM | 5.9 | 0.3% | Aug 31, 2022 | Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (L... |
| CVE-2022-2590 | HIGH | 7 | 0.9% | Aug 31, 2022 | A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of pr... |
| CVE-2022-2521 | MEDIUM | 6.5 | 0.9% | Aug 31, 2022 | It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 calle... |
| CVE-2022-2520 | MEDIUM | 6.5 | 0.9% | Aug 31, 2022 | A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can c... |
| CVE-2022-2519 | MEDIUM | 6.5 | 0.9% | Aug 31, 2022 | There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1 |
| CVE-2022-2485 | HIGH | 7.5 | 0.4% | Aug 31, 2022 | Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device resp... |
| CVE-2022-2466 | CRITICAL | 9.8 | 1.4% | Aug 31, 2022 | It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavio... |
| CVE-2022-2220 | — | — | — | Aug 31, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-2153 | MEDIUM | 5.5 | 0.4% | Aug 31, 2022 | A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbeh... |
| CVE-2022-2132 | HIGH | 8.6 | 1.7% | Aug 31, 2022 | A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of ser... |
| CVE-2022-2044 | HIGH | 8.2 | 0.6% | Aug 31, 2022 | MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that may allow an attacker to overwrite ... |
| CVE-2022-2043 | HIGH | 7.5 | 0.7% | Aug 31, 2022 | MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that can cause the device to become unre... |
| CVE-2022-2006 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | AutomationDirect DirectLOGIC has a DLL vulnerability in the install directory that may allow an attacker to execute code... |
| CVE-2022-2005 | HIGH | 7.5 | 0.4% | Aug 31, 2022 | AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server... |
| CVE-2022-2004 | HIGH | 7.5 | 0.8% | Aug 31, 2022 | AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to preven... |
| CVE-2022-2003 | CRITICAL | 9.1 | 0.6% | Aug 31, 2022 | AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cau... |
| CVE-2022-28625 | MEDIUM | 5.5 | 0.2% | Aug 31, 2022 | A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now