2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34375 | MEDIUM | 6.5 | 1.1% | Aug 30, 2022 | Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote au... |
| CVE-2022-34374 | HIGH | 8.8 | 1.4% | Aug 30, 2022 | Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authentic... |
| CVE-2022-34368 | MEDIUM | 6.5 | 0.3% | Aug 30, 2022 | Dell EMC NetWorker 19.2.1.x 19.3.x, 19.4.x, 19.5.x, 19.6.x and 19.7.0.0 contain an Improper Handling of Insufficient Per... |
| CVE-2022-33935 | MEDIUM | 5.4 | 0.4% | Aug 30, 2022 | Dell EMC Data Protection Advisor versions 19.6 and earlier, contains a Stored Cross Site Scripting, an attacker could po... |
| CVE-2022-31232 | CRITICAL | 9.8 | 0.8% | Aug 30, 2022 | SmartFabric storage software version 1.0.0 contains a Command-Injection vulnerability. A remote unauthenticated attacker... |
| CVE-2022-37237 | HIGH | 7.5 | 0.7% | Aug 30, 2022 | An attacker can send malicious RTMP requests to make the ZLMediaKit server crash remotely. Affected version is below com... |
| CVE-2022-37176 | CRITICAL | 9.8 | 1.0% | Aug 30, 2022 | Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi... |
| CVE-2022-36552 | HIGH | 7.5 | 0.7% | Aug 30, 2022 | Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which ... |
| CVE-2022-37149 | CRITICAL | 9.8 | 2.8% | Aug 30, 2022 | WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the f... |
| CVE-2022-3063 | — | — | — | Aug 30, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al... |
| CVE-2022-3022 | — | — | — | Aug 30, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al... |
| CVE-2022-2330 | MEDIUM | 6.5 | 0.7% | Aug 30, 2022 | Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows... |
| CVE-2022-39028 | HIGH | 7.5 | 1.6% | Aug 30, 2022 | telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference v... |
| CVE-2022-38118 | HIGH | 8.8 | 1.3% | Aug 30, 2022 | OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user p... |
| CVE-2022-38116 | CRITICAL | 9.8 | 0.9% | Aug 30, 2022 | Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source cod... |
| CVE-2022-26529 | MEDIUM | 6.5 | 0.4% | Aug 30, 2022 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmente... |
| CVE-2022-26528 | MEDIUM | 6.5 | 0.4% | Aug 30, 2022 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the leng... |
| CVE-2022-26527 | MEDIUM | 6.5 | 0.4% | Aug 30, 2022 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size... |
| CVE-2022-25887 | HIGH | 7.5 | 1.1% | Aug 30, 2022 | The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure gl... |
| CVE-2022-25857 | HIGH | 7.5 | 2.1% | Aug 30, 2022 | The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested de... |
| CVE-2022-25646 | MEDIUM | 6.1 | 0.7% | Aug 30, 2022 | All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of v... |
| CVE-2022-25635 | MEDIUM | 6.5 | 0.3% | Aug 30, 2022 | Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcas... |
| CVE-2022-24107 | HIGH | 7.8 | 0.3% | Aug 30, 2022 | Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc. |
| CVE-2022-24106 | HIGH | 7.8 | 0.3% | Aug 30, 2022 | In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the fi... |
| CVE-2022-38784 | HIGH | 7.8 | 0.6% | Aug 30, 2022 | Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now