2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28374 | HIGH | 8.8 | 1.8% | Jul 14, 2022 | Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the DM... |
| CVE-2022-28373 | CRITICAL | 9.8 | 1.8% | Jul 14, 2022 | Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not properly sanitize user-controlled parameters within the crt... |
| CVE-2022-28372 | HIGH | 7.5 | 0.7% | Jul 14, 2022 | On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC en... |
| CVE-2022-28371 | HIGH | 7.5 | 0.5% | Jul 14, 2022 | On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC en... |
| CVE-2022-28370 | HIGH | 7.5 | 0.3% | Jul 14, 2022 | On Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 devices, the RPC endpoint crtc_fw_upgrade provides a means of pr... |
| CVE-2022-28369 | CRITICAL | 9.8 | 1.3% | Jul 14, 2022 | Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 does not validate the user-provided URL within the crtcmode function... |
| CVE-2022-2396 | MEDIUM | 5.4 | 0.5% | Jul 14, 2022 | A vulnerability classified as problematic was found in SourceCodester Simple e-Learning System 1.0. Affected by this vul... |
| CVE-2022-25803 | MEDIUM | 6.1 | 0.4% | Jul 14, 2022 | Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search. |
| CVE-2022-25802 | MEDIUM | 6.1 | 0.6% | Jul 14, 2022 | Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attac... |
| CVE-2022-25801 | CRITICAL | 9.1 | 0.7% | Jul 14, 2022 | Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools. |
| CVE-2022-25800 | CRITICAL | 9.1 | 0.7% | Jul 14, 2022 | Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool. |
| CVE-2022-35857 | CRITICAL | 9.8 | 1.4% | Jul 13, 2022 | kvf-admin through 2022-02-12 allows remote attackers to execute arbitrary code because deserialization is mishandled. Th... |
| CVE-2022-34765 | MEDIUM | 5.3 | 0.5% | Jul 13, 2022 | A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware i... |
| CVE-2022-34764 | HIGH | 7.5 | 0.6% | Jul 13, 2022 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause... |
| CVE-2022-34763 | HIGH | 7.5 | 0.3% | Jul 13, 2022 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists that could cause loading of unauthorized ... |
| CVE-2022-34762 | HIGH | 7.5 | 0.6% | Jul 13, 2022 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could... |
| CVE-2022-34761 | HIGH | 7.5 | 0.8% | Jul 13, 2022 | A CWE-476: NULL Pointer Dereference vulnerability exists that could cause a denial of service of the webserver when pars... |
| CVE-2022-34760 | HIGH | 7.5 | 0.7% | Jul 13, 2022 | A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of serv... |
| CVE-2022-34759 | HIGH | 7.5 | 0.7% | Jul 13, 2022 | A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to imprope... |
| CVE-2022-34758 | MEDIUM | 4.9 | 0.4% | Jul 13, 2022 | A CWE-20: Improper Input Validation vulnerability exists that could cause the device watchdog function to be disabled if... |
| CVE-2022-34757 | MEDIUM | 5.3 | 0.3% | Jul 13, 2022 | A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists where weak cipher suites can be used fo... |
| CVE-2022-34756 | CRITICAL | 9.8 | 1.3% | Jul 13, 2022 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or... |
| CVE-2022-34754 | MEDIUM | 6.8 | 0.3% | Jul 13, 2022 | A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing cred... |
| CVE-2022-34753 | HIGH | 8.8 | 71.1% | Jul 13, 2022 | A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exist... |
| CVE-2022-32117 | HIGH | 7.8 | 0.3% | Jul 13, 2022 | Jerryscript v2.4.0 was discovered to contain a stack buffer overflow via the function jerryx_print_unhandled_exception i... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now