2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34600CRITICAL9.8H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EditSTList interface at /goform/aspFor...
CVE-2022-34599CRITICAL9.8H3C Magic R200 R200V200R004L02 was discovered to contain a stack overflow via the EdittriggerList interface at /goform/a...
CVE-2022-36322HIGH8.8In JetBrains TeamCity before 2022.04.2 build parameter injection was possible
CVE-2022-36321MEDIUM6.5In JetBrains TeamCity before 2022.04.2 the private SSH key could be written to the build log in some cases
CVE-2022-24660HIGH7.5The debug interface of Goldshell ASIC Miners v2.2.1 and below was discovered to be exposed publicly on the web interface...
CVE-2022-24659HIGH7.5Goldshell ASIC Miners v2.2.1 and below was discovered to contain a path traversal vulnerability which allows unauthentic...
CVE-2022-24657CRITICAL9.8Goldshell ASIC Miners v2.1.x was discovered to contain hardcoded credentials which allow attackers to remotely connect v...
CVE-2022-2492HIGH8.8A vulnerability was found in SourceCodester Library Management System 1.0 and classified as critical. This issue affects...
CVE-2022-2491HIGH8.8A vulnerability has been found in SourceCodester Library Management System 1.0 and classified as critical. This vulnerab...
CVE-2022-2490HIGH8.8A vulnerability classified as critical has been found in SourceCodester Simple E-Learning System 1.0. Affected is an unk...
CVE-2022-2489HIGH8.8A vulnerability was found in SourceCodester Simple E-Learning System 1.0. It has been rated as critical. This issue affe...
CVE-2022-2488CRITICAL9.8A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown pro...
CVE-2022-2487CRITICAL9.8A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unk...
CVE-2022-2486CRITICAL9.8A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown par...
CVE-2022-31250HIGH7.8A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escal...
CVE-2022-34866HIGH7.8Passage Drive versions v1.4.0 to v1.5.1.0 and Passage Drive for Box version v1.0.0 contain an insufficient data verifica...
CVE-2022-33967HIGH7.8squashfs filesystem implementation of U-Boot versions from v2020.10-rc2 to v2022.07-rc5 contains a heap-based buffer ove...
CVE-2022-32962MEDIUM6.8HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker c...
CVE-2022-32961MEDIUM6.8HICOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC...
CVE-2022-32960MEDIUM6.8HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC...
CVE-2022-32959MEDIUM6.8HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC...
CVE-2022-32958MEDIUM6.5A remote attacker with general user privilege can send a message to Teamplus Pro’s chat group that exceeds message size ...
CVE-2022-32458HIGH7.5Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An un...
CVE-2022-32457MEDIUM5.3Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack...
CVE-2022-32456CRITICAL9.8Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitra...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now