2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2672HIGH8.8A vulnerability was found in SourceCodester Garage Management System. It has been classified as critical. Affected is an...
CVE-2022-2671HIGH8.8A vulnerability was found in SourceCodester Garage Management System and classified as critical. This issue affects some...
CVE-2022-2667HIGH8.8A vulnerability was found in SourceCodester Loan Management System and classified as critical. This issue affects some u...
CVE-2022-2665HIGH8.8A vulnerability classified as critical was found in SourceCodester Simple E-Learning System. Affected by this vulnerabil...
CVE-2022-2664CRITICAL9.8A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown funct...
CVE-2022-2636HIGH8.8Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.
CVE-2022-2626HIGH7.2Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
CVE-2022-37434CRITICAL9.8zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header...
CVE-2022-37431MEDIUM6.1A Reflected Cross-site scripting (XSS) issue was discovered in dotCMS Core through 22.06. This occurs in the admin porta...
CVE-2022-37416MEDIUM6.5Ittiam libmpeg2 before 2022-07-27 uses memcpy with overlapping memory blocks in impeg2_mc_fullx_fully_8x8.
CVE-2022-21186CRITICAL9.8The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRep...
CVE-2022-37415HIGH7.8The Uniwill SparkIO.sys driver 1.0 is vulnerable to a stack-based buffer overflow via IOCTL 0x40002008.
CVE-2022-37030HIGH7.8Weak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a loc...
CVE-2022-35930HIGH8.8PolicyController is a utility used to enforce supply chain policy in Kubernetes clusters. In versions prior to 0.2.1 Pol...
CVE-2022-31793HIGH7.5do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL wi...
CVE-2022-35927CRITICAL9.8Contiki-NG is an open-source, cross-platform operating system for IoT devices. In the RPL-Classic routing protocol imple...
CVE-2022-35926HIGH7.5Contiki-NG is an open-source, cross-platform operating system for IoT devices. Because of insufficient validation of IPv...
CVE-2022-35858HIGH7.8The TEE_PopulateTransientObject and __utee_from_attr functions in Samsung mTower 0.3.0 allow a trusted application to tr...
CVE-2022-35144MEDIUM4.8Renato v0.17.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2022-35143CRITICAL9.8Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force...
CVE-2022-35142HIGH7.5An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the S...
CVE-2022-35929CRITICAL9.8cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive i...
CVE-2022-34993CRITICAL9.8Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample.
CVE-2022-34970CRITICAL9.8Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitati...
CVE-2022-35735HIGH7.2In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now