2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28374HIGH8.8Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DM...
CVE-2022-28373CRITICAL9.8Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crt...
CVE-2022-28372HIGH7.5On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC en...
CVE-2022-28371HIGH7.5On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC en...
CVE-2022-28370HIGH7.5On Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 devices, the RPC endpoint crtc_fw_upgrade provides a means of pr...
CVE-2022-28369CRITICAL9.8Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function...
CVE-2022-2396MEDIUM5.4A vulnerability classified as problematic was found in SourceCodester Simple e-Learning System 1.0. Affected by this vul...
CVE-2022-25803MEDIUM6.1Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.
CVE-2022-25802MEDIUM6.1Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attac...
CVE-2022-25801CRITICAL9.1Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.
CVE-2022-25800CRITICAL9.1Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.
CVE-2022-35857CRITICAL9.8kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. Th...
CVE-2022-34765MEDIUM5.3A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware i...
CVE-2022-34764HIGH7.5A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause...
CVE-2022-34763HIGH7.5A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists that could cause loading of unauthorized ...
CVE-2022-34762HIGH7.5A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could...
CVE-2022-34761HIGH7.5A CWE-476: NULL Pointer Dereference vulnerability exists that could cause a denial of service of the webserver when pars...
CVE-2022-34760HIGH7.5A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of serv...
CVE-2022-34759HIGH7.5A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to imprope...
CVE-2022-34758MEDIUM4.9A CWE-20: Improper Input Validation vulnerability exists that could cause the device watchdog function to be disabled if...
CVE-2022-34757MEDIUM5.3A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists where weak cipher suites can be used fo...
CVE-2022-34756CRITICAL9.8A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or...
CVE-2022-34754MEDIUM6.8A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing cred...
CVE-2022-34753HIGH8.8A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exist...
CVE-2022-32117HIGH7.8Jerryscript v2.4.0 was discovered to contain a stack buffer overflow via the function jerryx_print_unhandled_exception i...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now