2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32744 | HIGH | 8.8 | 1.0% | Aug 25, 2022 | A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpa... |
| CVE-2022-32742 | MEDIUM | 4.3 | 1.0% | Aug 25, 2022 | A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enoug... |
| CVE-2022-2991 | MEDIUM | 6.7 | 0.4% | Aug 25, 2022 | A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem. The issue results from the lack of prop... |
| CVE-2022-2959 | HIGH | 7 | 0.4% | Aug 25, 2022 | A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific f... |
| CVE-2022-2465 | HIGH | 7.8 | 0.3% | Aug 25, 2022 | Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted... |
| CVE-2022-2464 | HIGH | 7.8 | 0.3% | Aug 25, 2022 | Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability... |
| CVE-2022-2463 | HIGH | 7.8 | 2.6% | Aug 25, 2022 | Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability... |
| CVE-2022-2255 | HIGH | 7.5 | 0.7% | Aug 25, 2022 | A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, all... |
| CVE-2022-2031 | HIGH | 8.8 | 1.0% | Aug 25, 2022 | A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and... |
| CVE-2022-23715 | MEDIUM | 6.5 | 0.7% | Aug 25, 2022 | A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwo... |
| CVE-2022-23235 | MEDIUM | 5.3 | 0.5% | Aug 25, 2022 | Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.10P1 are susceptible to a... |
| CVE-2022-0135 | HIGH | 7.8 | 0.4% | Aug 25, 2022 | An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a maliciou... |
| CVE-2022-37162 | MEDIUM | 5.4 | 0.6% | Aug 25, 2022 | Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution... |
| CVE-2022-37161 | MEDIUM | 6.1 | 0.5% | Aug 25, 2022 | Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload. |
| CVE-2022-37160 | MEDIUM | 5.4 | 0.5% | Aug 25, 2022 | Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privil... |
| CVE-2022-37159 | CRITICAL | 9.8 | 24.9% | Aug 25, 2022 | Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload. |
| CVE-2022-37158 | CRITICAL | 9.8 | 0.8% | Aug 25, 2022 | RuoYi v3.8.3 has a Weak password vulnerability in the management system. |
| CVE-2022-37292 | MEDIUM | 5.5 | 0.3% | Aug 25, 2022 | Tenda AX12 V22.03.01.21_CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub_42FDE4 function, whic... |
| CVE-2022-37238 | MEDIUM | 5.4 | 0.5% | Aug 25, 2022 | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the current... |
| CVE-2022-37824 | HIGH | 7.8 | 0.3% | Aug 25, 2022 | Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWif... |
| CVE-2022-37823 | HIGH | 7.8 | 0.3% | Aug 25, 2022 | Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetVirtualSe... |
| CVE-2022-37822 | HIGH | 7.8 | 0.3% | Aug 25, 2022 | Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetRouteStatic. |
| CVE-2022-37821 | HIGH | 7.8 | 0.3% | Aug 25, 2022 | Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ProvinceCode parameter in the function formSetP... |
| CVE-2022-37820 | HIGH | 7.8 | 0.3% | Aug 25, 2022 | Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ddnsEn parameter in the function formSetSysTool... |
| CVE-2022-37819 | HIGH | 7.8 | 0.3% | Aug 25, 2022 | Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the timezone parameter in the function fromSetSysTi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now