2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36588 | CRITICAL | 9.8 | 1.5% | Sep 8, 2022 | In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused ... |
| CVE-2022-36586 | CRITICAL | 9.8 | 0.8% | Sep 8, 2022 | In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0... |
| CVE-2022-36585 | CRITICAL | 9.8 | 0.8% | Sep 7, 2022 | In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused ... |
| CVE-2022-36089 | CRITICAL | 9.8 | 0.7% | Sep 7, 2022 | KubeVela is an application delivery platform Users using KubeVela's VelaUX APIServer could be affected by an authenticat... |
| CVE-2022-36086 | CRITICAL | 9.8 | 0.7% | Sep 7, 2022 | linked_list_allocator is an allocator usable for no_std systems. Prior to version 0.10.2, the heap initialization method... |
| CVE-2022-38250 | CRITICAL | 9.8 | 2.5% | Sep 7, 2022 | Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs p... |
| CVE-2022-3130 | CRITICAL | 9.8 | 0.8% | Sep 7, 2022 | A vulnerability classified as critical has been found in codeprojects Online Driving School. This affects an unknown par... |
| CVE-2022-3129 | CRITICAL | 9.8 | 0.8% | Sep 7, 2022 | A vulnerability was found in codeprojects Online Driving School. It has been rated as critical. Affected by this issue i... |
| CVE-2022-38314 | CRITICAL | 9.8 | 0.9% | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /go... |
| CVE-2022-38313 | CRITICAL | 9.8 | 0.9% | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /go... |
| CVE-2022-38312 | CRITICAL | 9.8 | 0.9% | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /go... |
| CVE-2022-38311 | CRITICAL | 9.8 | 0.9% | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /go... |
| CVE-2022-38310 | CRITICAL | 9.8 | 0.9% | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /go... |
| CVE-2022-38309 | CRITICAL | 9.8 | 0.9% | Sep 7, 2022 | Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /go... |
| CVE-2022-36660 | CRITICAL | 9.8 | 0.8% | Sep 7, 2022 | xhyve commit dfbe09b was discovered to contain a stack buffer overflow via the component pci_vtrnd_notify(). |
| CVE-2022-36587 | CRITICAL | 9.8 | 0.8% | Sep 7, 2022 | In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by sprintf in function ... |
| CVE-2022-31149 | CRITICAL | 9.6 | 1.0% | Sep 7, 2022 | ActivityWatch open-source automated time tracker. Versions prior to 0.12.0b2 are vulnerable to DNS rebinding attacks. Th... |
| CVE-2022-31247 | CRITICAL | 9.1 | 0.8% | Sep 7, 2022 | An Improper Authorization vulnerability in SUSE Rancher, allows any user who has permissions to create/edit cluster role... |
| CVE-2022-37344 | CRITICAL | 9.8 | 0.7% | Sep 6, 2022 | Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at WordPress. |
| CVE-2022-36427 | CRITICAL | 9.8 | 0.7% | Sep 6, 2022 | Missing Access Control vulnerability in About Rentals. Inc. About Rentals plugin <= 1.5 at WordPress. |
| CVE-2022-36387 | CRITICAL | 9.8 | 0.7% | Sep 6, 2022 | Broken Access Control vulnerability in Alessio Caiazza's About Me plugin <= 1.0.12 at WordPress. |
| CVE-2022-1525 | CRITICAL | 9.1 | 0.7% | Sep 6, 2022 | The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-602: Client-Side... |
| CVE-2022-1368 | CRITICAL | 9.8 | 0.8% | Sep 6, 2022 | The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Aut... |
| CVE-2022-36067 | CRITICAL | 10 | 47.9% | Sep 6, 2022 | vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.... |
| CVE-2022-36663 | CRITICAL | 9.8 | 1.9% | Sep 6, 2022 | Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted req... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now