2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25657 | CRITICAL | 9.8 | 0.3% | Sep 2, 2022 | Memory corruption due to buffer overflow occurs while processing invalid MKV clip which has invalid seek header in Snapd... |
| CVE-2022-22096 | CRITICAL | 9.8 | 0.4% | Sep 2, 2022 | Memory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length pa... |
| CVE-2022-22062 | CRITICAL | 9.1 | 0.3% | Sep 2, 2022 | An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snap... |
| CVE-2022-38054 | CRITICAL | 9.8 | 1.8% | Sep 2, 2022 | In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixa... |
| CVE-2022-29063 | CRITICAL | 9.8 | 3.5% | Sep 2, 2022 | The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In... |
| CVE-2022-25371 | CRITICAL | 9.8 | 3.9% | Sep 2, 2022 | Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and re... |
| CVE-2022-36609 | CRITICAL | 9.8 | 0.6% | Sep 2, 2022 | Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ... |
| CVE-2022-36594 | CRITICAL | 9.8 | 0.7% | Sep 2, 2022 | Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds... |
| CVE-2022-36759 | CRITICAL | 9.8 | 0.9% | Sep 2, 2022 | Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?r... |
| CVE-2022-36601 | CRITICAL | 9.8 | 1.0% | Sep 1, 2022 | The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows ... |
| CVE-2022-34379 | CRITICAL | 9.8 | 0.9% | Sep 1, 2022 | Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with ... |
| CVE-2022-34372 | CRITICAL | 9.1 | 1.0% | Sep 1, 2022 | Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unau... |
| CVE-2022-36672 | CRITICAL | 9.8 | 0.9% | Sep 1, 2022 | Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability ... |
| CVE-2022-36130 | CRITICAL | 9.9 | 0.4% | Sep 1, 2022 | HashiCorp Boundary up to 0.10.1 did not properly perform data integrity checks to ensure the resources were associated w... |
| CVE-2022-37130 | CRITICAL | 9.8 | 26.3% | Aug 31, 2022 | In D-Link DIR-816 A2_v1.10CNB04, DIR-878 DIR_878_FW1.30B08.img a command injection vulnerability occurs in /goform/Diagn... |
| CVE-2022-37125 | CRITICAL | 9.8 | 3.2% | Aug 31, 2022 | D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Command injection via /goform/NTPSyncWithHost. |
| CVE-2022-36202 | CRITICAL | 9.8 | 0.9% | Aug 31, 2022 | Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php... |
| CVE-2022-36201 | CRITICAL | 9.8 | 1.7% | Aug 31, 2022 | Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php. |
| CVE-2022-37128 | CRITICAL | 9.8 | 21.2% | Aug 31, 2022 | In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end. |
| CVE-2022-36566 | CRITICAL | 9.8 | 2.1% | Aug 31, 2022 | Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function. |
| CVE-2022-30318 | CRITICAL | 9.8 | 1.3% | Aug 31, 2022 | Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell Cont... |
| CVE-2022-30317 | CRITICAL | 9.1 | 0.7% | Aug 31, 2022 | Honeywell Experion LX through 2022-05-06 has Missing Authentication for a Critical Function. According to FSCT-2022-0055... |
| CVE-2022-2466 | CRITICAL | 9.8 | 1.4% | Aug 31, 2022 | It was found that Quarkus 2.10.x does not terminate HTTP requests header context which may lead to unpredictable behavio... |
| CVE-2022-2003 | CRITICAL | 9.1 | 0.6% | Aug 31, 2022 | AutomationDirect DirectLOGIC is vulnerable to a specifically crafted serial message to the CPU serial port that will cau... |
| CVE-2022-21941 | CRITICAL | 9.8 | 2.0% | Aug 31, 2022 | All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauth... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now