2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34600 | CRITICAL | 9.8 | 1.0% | Jul 20, 2022 | H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditSTList interface at /goform/aspFor... |
| CVE-2022-34599 | CRITICAL | 9.8 | 1.0% | Jul 20, 2022 | H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EdittriggerList interface at /goform/a... |
| CVE-2022-36322 | HIGH | 8.8 | 0.6% | Jul 20, 2022 | In JetBrains TeamCity before 2022.04.2 build parameter injection was possible |
| CVE-2022-36321 | MEDIUM | 6.5 | 1.6% | Jul 20, 2022 | In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases |
| CVE-2022-24660 | HIGH | 7.5 | 0.5% | Jul 20, 2022 | The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface... |
| CVE-2022-24659 | HIGH | 7.5 | 1.3% | Jul 20, 2022 | Goldshell ASIC Miners v2.2.1 and below was discovered to contain a path traversal vulnerability which allows unauthentic... |
| CVE-2022-24657 | CRITICAL | 9.8 | 0.9% | Jul 20, 2022 | Goldshell ASIC Miners v2.1.x was discovered to contain hardcoded credentials which allow attackers to remotely connect v... |
| CVE-2022-2492 | HIGH | 8.8 | 0.6% | Jul 20, 2022 | A vulnerability was found in SourceCodester Library Management System 1.0 and classified as critical. This issue affects... |
| CVE-2022-2491 | HIGH | 8.8 | 0.6% | Jul 20, 2022 | A vulnerability has been found in SourceCodester Library Management System 1.0 and classified as critical. This vulnerab... |
| CVE-2022-2490 | HIGH | 8.8 | 0.6% | Jul 20, 2022 | A vulnerability classified as critical has been found in SourceCodester Simple E-Learning System 1.0. Affected is an unk... |
| CVE-2022-2489 | HIGH | 8.8 | 0.6% | Jul 20, 2022 | A vulnerability was found in SourceCodester Simple E-Learning System 1.0. It has been rated as critical. This issue affe... |
| CVE-2022-2488 | CRITICAL | 9.8 | 28.7% | Jul 20, 2022 | A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown pro... |
| CVE-2022-2487 | CRITICAL | 9.8 | 79.5% | Jul 20, 2022 | A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unk... |
| CVE-2022-2486 | CRITICAL | 9.8 | 26.1% | Jul 20, 2022 | A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown par... |
| CVE-2022-31250 | HIGH | 7.8 | 0.3% | Jul 20, 2022 | A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escal... |
| CVE-2022-34866 | HIGH | 7.8 | 0.2% | Jul 20, 2022 | Passage Drive versions v1.4.0 to v1.5.1.0 and Passage Drive for Box version v1.0.0 contain an insufficient data verifica... |
| CVE-2022-33967 | HIGH | 7.8 | 0.5% | Jul 20, 2022 | squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer ove... |
| CVE-2022-32962 | MEDIUM | 6.8 | 0.2% | Jul 20, 2022 | HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker c... |
| CVE-2022-32961 | MEDIUM | 6.8 | 0.2% | Jul 20, 2022 | HICOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC... |
| CVE-2022-32960 | MEDIUM | 6.8 | 0.2% | Jul 20, 2022 | HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC... |
| CVE-2022-32959 | MEDIUM | 6.8 | 0.2% | Jul 20, 2022 | HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC... |
| CVE-2022-32958 | MEDIUM | 6.5 | 0.8% | Jul 20, 2022 | A remote attacker with general user privilege can send a message to Teamplus Pro’s chat group that exceeds message size ... |
| CVE-2022-32458 | HIGH | 7.5 | 0.9% | Jul 20, 2022 | Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An un... |
| CVE-2022-32457 | MEDIUM | 5.3 | 0.7% | Jul 20, 2022 | Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack... |
| CVE-2022-32456 | CRITICAL | 9.8 | 1.3% | Jul 20, 2022 | Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitra... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now