2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36010CRITICAL9.8This library allows strings to be parsed as functions and stored as a specialized component, [`JsonFunctionValue`](https...
CVE-2022-35978CRITICAL10Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can se...
CVE-2022-24654MEDIUM5.4Authenticated stored cross-site scripting (XSS) vulnerability in "Field Server Address" field in INTELBRAS ATA 200 Firmw...
CVE-2022-36526HIGH7.5D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Authentication Bypass via functi...
CVE-2022-36525CRITICAL9.8D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Buffer Overflow via authenticati...
CVE-2022-36524HIGH7.5D-Link GO-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to Static Default Credentials via /...
CVE-2022-36523CRITICAL9.8D-Link Go-RT-AC750 GORTAC750_revA_v101b03 & GO-RT-AC750_revB_FWv200b02 is vulnerable to command injection via /htdocs/up...
CVE-2022-35624HIGH8.8In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented packets...
CVE-2022-35623HIGH8.8In Nordic nRF5 SDK for Mesh 5.0, a heap overflow vulnerability can be triggered by sending a series of segmented control...
CVE-2022-2824MEDIUM5.4Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.
CVE-2022-33991MEDIUM5.3dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking disabled) bit set to 1. This...
CVE-2022-33990HIGH7.5Misinterpretation of special domain name characters in dproxy-nexgen (aka dproxy nexgen) leads to cache poisoning becaus...
CVE-2022-33989MEDIUM5.3dproxy-nexgen (aka dproxy nexgen) uses a static UDP source port (selected randomly only at boot time) in upstream querie...
CVE-2022-33988HIGH7.5dproxy-nexgen (aka dproxy nexgen) re-uses the DNS transaction id (TXID) value from client queries, which allows attacker...
CVE-2022-36262CRITICAL9.8An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modify...
CVE-2022-34294CRITICAL9.8totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows DNS cache poisoning becau...
CVE-2022-33993MEDIUM5.3Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoni...
CVE-2022-33992HIGH7.5DNRD (aka Domain Name Relay Daemon) 2.20.3 forwards and caches DNS queries with the CD (aka checking disabled) bit set t...
CVE-2022-38223HIGH7.8There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTM...
CVE-2022-38221CRITICAL9.8A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 be...
CVE-2022-37401HIGH8.8Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored...
CVE-2022-37400HIGH8.8Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored...
CVE-2022-36007LOW3.3Venice is a Clojure inspired sandboxed Lisp dialect with excellent Java interoperability. A partial path traversal issue...
CVE-2022-36006HIGH8.8Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedic...
CVE-2022-35961MEDIUM6.5OpenZeppelin Contracts is a library for secure smart contract development. The functions `ECDSA.recover` and `ECDSA.tryR...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now