2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-32744HIGH8.8A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it. By encrypting forged kpa...
CVE-2022-32742MEDIUM4.3A flaw was found in Samba. Some SMB1 write requests were not correctly range-checked to ensure the client had sent enoug...
CVE-2022-2991MEDIUM6.7A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem. The issue results from the lack of prop...
CVE-2022-2959HIGH7A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific f...
CVE-2022-2465HIGH7.8Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted...
CVE-2022-2464HIGH7.8Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability...
CVE-2022-2463HIGH7.8Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability...
CVE-2022-2255HIGH7.5A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, all...
CVE-2022-2031HIGH8.8A flaw was found in Samba. The security vulnerability occurs when KDC and the kpasswd service share a single account and...
CVE-2022-23715MEDIUM6.5A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwo...
CVE-2022-23235MEDIUM5.3Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.10P1 are susceptible to a...
CVE-2022-0135HIGH7.8An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a maliciou...
CVE-2022-37162MEDIUM5.4Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS). An attacker can obtain javascript code execution...
CVE-2022-37161MEDIUM6.1Claroline 13.5.7 and prior is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
CVE-2022-37160MEDIUM5.4Claroline 13.5.7 and prior allows an authenticated attacker to elevate privileges via the arbitrary creation of a privil...
CVE-2022-37159CRITICAL9.8Claroline 13.5.7 and prior is vulnerable to Remote code execution via arbitrary file upload.
CVE-2022-37158CRITICAL9.8RuoYi v3.8.3 has a Weak password vulnerability in the management system.
CVE-2022-37292MEDIUM5.5Tenda AX12 V22.03.01.21_CN is vulnerable to Buffer Overflow. This overflow is triggered in the sub_42FDE4 function, whic...
CVE-2022-37238MEDIUM5.4MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the current...
CVE-2022-37824HIGH7.8Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWif...
CVE-2022-37823HIGH7.8Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function formSetVirtualSe...
CVE-2022-37822HIGH7.8Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the function fromSetRouteStatic.
CVE-2022-37821HIGH7.8Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ProvinceCode parameter in the function formSetP...
CVE-2022-37820HIGH7.8Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the ddnsEn parameter in the function formSetSysTool...
CVE-2022-37819HIGH7.8Tenda AX1803 v1.0.0.1 was discovered to contain a stack overflow via the timezone parameter in the function fromSetSysTi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now