2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36566CRITICAL9.8Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.
CVE-2022-38152HIGH7.5An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is cal...
CVE-2022-3028HIGH7A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple ca...
CVE-2022-37122HIGH7.5Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 s...
CVE-2022-30318CRITICAL9.8Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell Cont...
CVE-2022-30317CRITICAL9.1Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055...
CVE-2022-2866HIGH7.8FATEK FvDesigner version 1.5.103 and prior is vulnerable to an out-of-bounds write while processing project files. If a ...
CVE-2022-2759HIGH8.6Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions w...
CVE-2022-2758MEDIUM5.9Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (L...
CVE-2022-2590HIGH7A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of pr...
CVE-2022-2521MEDIUM6.5It was found in libtiff 4.4.0rc1 that there is an invalid pointer free operation in TIFFClose() at tif_close.c:131 calle...
CVE-2022-2520MEDIUM6.5A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can c...
CVE-2022-2519MEDIUM6.5There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1
CVE-2022-2485HIGH7.5Any attempt (good or bad) to log into AutomationDirect Stride Field I/O with a web browser may result in the device resp...
CVE-2022-2466CRITICAL9.8It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavio...
CVE-2022-2220Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-2153MEDIUM5.5A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbeh...
CVE-2022-2132HIGH8.6A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of ser...
CVE-2022-2044HIGH8.2MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that may allow an attacker to overwrite ...
CVE-2022-2043HIGH7.5MOXA NPort 5110: Firmware Versions 2.10 is vulnerable to an out-of-bounds write that can cause the device to become unre...
CVE-2022-2006HIGH7.8AutomationDirect DirectLOGIC has a DLL vulnerability in the install directory that may allow an attacker to execute code...
CVE-2022-2005HIGH7.5AutomationDirect C-more EA9 HTTP webserver uses an insecure mechanism to transport credentials from client to web server...
CVE-2022-2004HIGH7.5AutomationDirect DirectLOGIC is vulnerable to a a specially crafted packet can be sent continuously to the PLC to preven...
CVE-2022-2003CRITICAL9.1AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cau...
CVE-2022-28625MEDIUM5.5A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now