2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34375MEDIUM6.5Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote au...
CVE-2022-34374HIGH8.8Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authentic...
CVE-2022-34368MEDIUM6.5Dell EMC NetWorker 19.2.1.x 19.3.x, 19.4.x, 19.5.x, 19.6.x and 19.7.0.0 contain an Improper Handling of Insufficient Per...
CVE-2022-33935MEDIUM5.4Dell EMC Data Protection Advisor versions 19.6 and earlier, contains a Stored Cross Site Scripting, an attacker could po...
CVE-2022-31232CRITICAL9.8SmartFabric storage software version 1.0.0 contains a Command-Injection vulnerability. A remote unauthenticated attacker...
CVE-2022-37237HIGH7.5An attacker can send malicious RTMP requests to make the ZLMediaKit server crash remotely. Affected version is below com...
CVE-2022-37176CRITICAL9.8Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows attackers to remove the Wi...
CVE-2022-36552HIGH7.5Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi-bin/DownloadFlash which ...
CVE-2022-37149CRITICAL9.8WAVLINK WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability when operating the f...
CVE-2022-3063Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al...
CVE-2022-3022Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al...
CVE-2022-2330MEDIUM6.5Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows...
CVE-2022-39028HIGH7.5telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference v...
CVE-2022-38118HIGH8.8OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user p...
CVE-2022-38116CRITICAL9.8Le-yan Personnel and Salary Management System has hard-coded database account and password within the website source cod...
CVE-2022-26529MEDIUM6.5Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmente...
CVE-2022-26528MEDIUM6.5Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the leng...
CVE-2022-26527MEDIUM6.5Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size...
CVE-2022-25887HIGH7.5The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure gl...
CVE-2022-25857HIGH7.5The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested de...
CVE-2022-25646MEDIUM6.1All versions of package x-data-spreadsheet are vulnerable to Cross-site Scripting (XSS) due to missing sanitization of v...
CVE-2022-25635MEDIUM6.5Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcas...
CVE-2022-24107HIGH7.8Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.
CVE-2022-24106HIGH7.8In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the fi...
CVE-2022-38784HIGH7.8Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now