2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36010 | CRITICAL | 9.8 | 1.2% | Aug 15, 2022 | This library allows strings to be parsed as functions and stored as a specialized component, [`JsonFunctionValue`](https... |
| CVE-2022-35978 | CRITICAL | 10 | 2.2% | Aug 15, 2022 | Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can se... |
| CVE-2022-24654 | MEDIUM | 5.4 | 1.1% | Aug 15, 2022 | Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmw... |
| CVE-2022-36526 | HIGH | 7.5 | 1.3% | Aug 15, 2022 | D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via functi... |
| CVE-2022-36525 | CRITICAL | 9.8 | 1.4% | Aug 15, 2022 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticati... |
| CVE-2022-36524 | HIGH | 7.5 | 0.9% | Aug 15, 2022 | D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /... |
| CVE-2022-36523 | CRITICAL | 9.8 | 2.1% | Aug 15, 2022 | D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/up... |
| CVE-2022-35624 | HIGH | 8.8 | 0.9% | Aug 15, 2022 | In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented packets... |
| CVE-2022-35623 | HIGH | 8.8 | 0.9% | Aug 15, 2022 | In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented control... |
| CVE-2022-2824 | MEDIUM | 5.4 | 0.6% | Aug 15, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1. |
| CVE-2022-33991 | MEDIUM | 5.3 | 0.8% | Aug 15, 2022 | dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This... |
| CVE-2022-33990 | HIGH | 7.5 | 0.9% | Aug 15, 2022 | Misinterpretation of special domain name characters in dproxy-nexgen (aka dproxy nexgen) leads to cache poisoning becaus... |
| CVE-2022-33989 | MEDIUM | 5.3 | 0.8% | Aug 15, 2022 | dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream querie... |
| CVE-2022-33988 | HIGH | 7.5 | 0.9% | Aug 15, 2022 | dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries, which allows attacker... |
| CVE-2022-36262 | CRITICAL | 9.8 | 1.5% | Aug 15, 2022 | An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modify... |
| CVE-2022-34294 | CRITICAL | 9.8 | 1.4% | Aug 15, 2022 | totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning becau... |
| CVE-2022-33993 | MEDIUM | 5.3 | 0.7% | Aug 15, 2022 | Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoni... |
| CVE-2022-33992 | HIGH | 7.5 | 0.8% | Aug 15, 2022 | DNRD (aka Domain Name Relay Daemon) 2.20.3 forwards and caches DNS queries with the CD (aka checking disabled) bit set t... |
| CVE-2022-38223 | HIGH | 7.8 | 0.4% | Aug 15, 2022 | There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTM... |
| CVE-2022-38221 | CRITICAL | 9.8 | 1.5% | Aug 15, 2022 | A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 be... |
| CVE-2022-37401 | HIGH | 8.8 | 1.4% | Aug 15, 2022 | Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored... |
| CVE-2022-37400 | HIGH | 8.8 | 0.8% | Aug 15, 2022 | Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored... |
| CVE-2022-36007 | LOW | 3.3 | 0.4% | Aug 15, 2022 | Venice is a Clojure inspired sandboxed Lisp dialect with excellent Java interoperability. A partial path traversal issue... |
| CVE-2022-36006 | HIGH | 8.8 | 1.3% | Aug 15, 2022 | Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedic... |
| CVE-2022-35961 | MEDIUM | 6.5 | 0.3% | Aug 15, 2022 | OpenZeppelin Contracts is a library for secure smart contract development. The functions `ECDSA.recover` and `ECDSA.tryR... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now