2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36061 | CRITICAL | 9.8 | 1.0% | Sep 6, 2022 | Elrond go is the go implementation for the Elrond Network protocol. In versions prior to 1.3.35, read only calls between... |
| CVE-2022-31789 | CRITICAL | 9.8 | 1.5% | Sep 6, 2022 | An integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buff... |
| CVE-2022-36425 | CRITICAL | 9.8 | 0.7% | Sep 6, 2022 | Broken Access Control vulnerability in Beaver Builder plugin <= 2.5.4.3 at WordPress. |
| CVE-2022-31860 | CRITICAL | 9.8 | 1.7% | Sep 6, 2022 | An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule... |
| CVE-2022-26447 | CRITICAL | 9.8 | 0.6% | Sep 6, 2022 | In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code ex... |
| CVE-2022-40111 | CRITICAL | 9.8 | 0.7% | Sep 6, 2022 | In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware... |
| CVE-2022-40109 | CRITICAL | 9.8 | 0.7% | Sep 6, 2022 | TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa. |
| CVE-2022-37843 | CRITICAL | 9.8 | 1.5% | Sep 6, 2022 | In TOTOLINK A860R V4.1.2cu.5182_B20201027 in cstecgi.cgi, the acquired parameters are directly put into the system for e... |
| CVE-2022-37842 | CRITICAL | 9.8 | 0.8% | Sep 6, 2022 | In TOTOLINK A860R V4.1.2cu.5182_B20201027, the parameters in infostat.cgi are not filtered, causing a buffer overflow vu... |
| CVE-2022-37840 | CRITICAL | 9.8 | 0.8% | Sep 6, 2022 | In TOTOLINK A860R V4.1.2cu.5182_B20201027, the main function in downloadfile.cgi has a buffer overflow vulnerability. |
| CVE-2022-37839 | CRITICAL | 9.8 | 0.8% | Sep 6, 2022 | TOTOLINK A860R V4.1.2cu.5182_B20201027 is vulnerable to Buffer Overflow via Cstecgi.cgi. |
| CVE-2022-36584 | CRITICAL | 9.8 | 0.8% | Sep 6, 2022 | In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, the getsinglepppuser function has a buffer overflow caused by sscanf. |
| CVE-2022-2714 | CRITICAL | 9.8 | 0.7% | Sep 6, 2022 | Improper Handling of Length Parameter Inconsistency in GitHub repository francoisjacquet/rosariosis prior to 10.0. |
| CVE-2022-34747 | CRITICAL | 9.8 | 1.5% | Sep 6, 2022 | A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to ach... |
| CVE-2022-31814 | CRITICAL | 9.8 | 86.4% | Sep 5, 2022 | pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metachar... |
| CVE-2022-3122 | CRITICAL | 9.8 | 0.6% | Sep 5, 2022 | A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. Affect... |
| CVE-2022-2830 | CRITICAL | 9.8 | 0.8% | Sep 5, 2022 | Deserialization of Untrusted Data vulnerability in the message processing component of Bitdefender GravityZone Console a... |
| CVE-2022-3120 | CRITICAL | 9.8 | 0.6% | Sep 5, 2022 | A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System. Affected by this v... |
| CVE-2022-3118 | CRITICAL | 9.8 | 0.7% | Sep 4, 2022 | A vulnerability was found in Sourcecodehero ERP System Project. It has been rated as critical. This issue affects some u... |
| CVE-2022-36642 | CRITICAL | 9.8 | 9.0% | Sep 2, 2022 | A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 all... |
| CVE-2022-36640 | CRITICAL | 9.8 | 2.0% | Sep 2, 2022 | influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers ... |
| CVE-2022-34371 | CRITICAL | 9.8 | 0.5% | Sep 2, 2022 | Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotect... |
| CVE-2022-25668 | CRITICAL | 9.8 | 0.3% | Sep 2, 2022 | Memory corruption in video driver due to double free while parsing ASF clip in Snapdragon Auto, Snapdragon Compute, Snap... |
| CVE-2022-25659 | CRITICAL | 9.8 | 0.3% | Sep 2, 2022 | Memory corruption due to buffer overflow while parsing MKV clips with invalid bitmap size in Snapdragon Auto, Snapdragon... |
| CVE-2022-25658 | CRITICAL | 9.8 | 0.3% | Sep 2, 2022 | Memory corruption due to incorrect pointer arithmetic when attempting to change the endianness in video parser function ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now