2022 CVE Vulnerabilities
27,541 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2672 | HIGH | 8.8 | 0.5% | Aug 5, 2022 | A vulnerability was found in SourceCodester Garage Management System. It has been classified as critical. Affected is an... |
| CVE-2022-2671 | HIGH | 8.8 | 0.5% | Aug 5, 2022 | A vulnerability was found in SourceCodester Garage Management System and classified as critical. This issue affects some... |
| CVE-2022-2667 | HIGH | 8.8 | 0.7% | Aug 5, 2022 | A vulnerability was found in SourceCodester Loan Management System and classified as critical. This issue affects some u... |
| CVE-2022-2665 | HIGH | 8.8 | 0.5% | Aug 5, 2022 | A vulnerability classified as critical was found in SourceCodester Simple E-Learning System. Affected by this vulnerabil... |
| CVE-2022-2664 | CRITICAL | 9.8 | 0.6% | Aug 5, 2022 | A vulnerability classified as critical has been found in Private Cloud Management Platform. Affected is an unknown funct... |
| CVE-2022-2636 | HIGH | 8.8 | 1.1% | Aug 5, 2022 | Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6. |
| CVE-2022-2626 | HIGH | 7.2 | 1.0% | Aug 5, 2022 | Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6. |
| CVE-2022-37434 | CRITICAL | 9.8 | 16.0% | Aug 5, 2022 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header... |
| CVE-2022-37431 | MEDIUM | 6.1 | 0.6% | Aug 5, 2022 | A Reflected Cross-site scripting (XSS) issue was discovered in dotCMS Core through 22.06. This occurs in the admin porta... |
| CVE-2022-37416 | MEDIUM | 6.5 | 0.8% | Aug 5, 2022 | Ittiam libmpeg2 before 2022-07-27 uses memcpy with overlapping memory blocks in impeg2_mc_fullx_fully_8x8. |
| CVE-2022-21186 | CRITICAL | 9.8 | 24.9% | Aug 5, 2022 | The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRep... |
| CVE-2022-37415 | HIGH | 7.8 | 0.4% | Aug 5, 2022 | The Uniwill SparkIO.sys driver 1.0 is vulnerable to a stack-based buffer overflow via IOCTL 0x40002008. |
| CVE-2022-37030 | HIGH | 7.8 | 0.3% | Aug 4, 2022 | Weak permissions on the configuration file in the PAM module in Grommunio Gromox 0.5 through 1.x before 1.28 allow a loc... |
| CVE-2022-35930 | HIGH | 8.8 | 0.5% | Aug 4, 2022 | PolicyController is a utility used to enforce supply chain policy in Kubernetes clusters. In versions prior to 0.2.1 Pol... |
| CVE-2022-31793 | HIGH | 7.5 | 11.4% | Aug 4, 2022 | do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL wi... |
| CVE-2022-35927 | CRITICAL | 9.8 | 1.6% | Aug 4, 2022 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. In the RPL-Classic routing protocol imple... |
| CVE-2022-35926 | HIGH | 7.5 | 0.9% | Aug 4, 2022 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. Because of insufficient validation of IPv... |
| CVE-2022-35858 | HIGH | 7.8 | 0.4% | Aug 4, 2022 | The TEE_PopulateTransientObject and __utee_from_attr functions in Samsung mTower 0.3.0 allow a trusted application to tr... |
| CVE-2022-35144 | MEDIUM | 4.8 | 0.7% | Aug 4, 2022 | Renato v0.17.0 was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2022-35143 | CRITICAL | 9.8 | 1.3% | Aug 4, 2022 | Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force... |
| CVE-2022-35142 | HIGH | 7.5 | 1.2% | Aug 4, 2022 | An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the S... |
| CVE-2022-35929 | CRITICAL | 9.8 | 0.5% | Aug 4, 2022 | cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive i... |
| CVE-2022-34993 | CRITICAL | 9.8 | 0.9% | Aug 4, 2022 | Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample. |
| CVE-2022-34970 | CRITICAL | 9.8 | 2.8% | Aug 4, 2022 | Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitati... |
| CVE-2022-35735 | HIGH | 7.2 | 0.8% | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, a... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now