2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20813 | MEDIUM | 5.9 | 1.0% | Jul 6, 2022 | Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TeleP... |
| CVE-2022-20812 | MEDIUM | 6.5 | 1.7% | Jul 6, 2022 | Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TeleP... |
| CVE-2022-20808 | MEDIUM | 6.5 | 0.9% | Jul 6, 2022 | A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to c... |
| CVE-2022-20800 | MEDIUM | 6.1 | 0.7% | Jul 6, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie... |
| CVE-2022-20791 | MEDIUM | 6.5 | 1.3% | Jul 6, 2022 | A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Comm... |
| CVE-2022-20768 | MEDIUM | 4.9 | 0.8% | Jul 6, 2022 | A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could all... |
| CVE-2022-20752 | MEDIUM | 5.3 | 0.9% | Jul 6, 2022 | A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Manag... |
| CVE-2022-33047 | CRITICAL | 9.8 | 1.2% | Jul 6, 2022 | OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c. |
| CVE-2022-2318 | MEDIUM | 5.5 | 0.4% | Jul 6, 2022 | There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers ... |
| CVE-2022-2316 | MEDIUM | 5.4 | 0.5% | Jul 6, 2022 | HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the render... |
| CVE-2022-31131 | MEDIUM | 4.3 | 0.6% | Jul 6, 2022 | Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were foun... |
| CVE-2022-31129 | HIGH | 7.5 | 3.9% | Jul 6, 2022 | moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of mo... |
| CVE-2022-31127 | MEDIUM | 6.1 | 0.9% | Jul 6, 2022 | NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromis... |
| CVE-2022-31126 | CRITICAL | 9.8 | 41.0% | Jul 6, 2022 | Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in R... |
| CVE-2022-31125 | CRITICAL | 9.8 | 15.9% | Jul 6, 2022 | Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in R... |
| CVE-2022-31124 | MEDIUM | 6.5 | 1.0% | Jul 6, 2022 | openssh_key_parser is an open source Python package providing utilities to parse and pack OpenSSH private and public key... |
| CVE-2022-31111 | MEDIUM | 5.3 | 1.0% | Jul 6, 2022 | Frontier is Substrate's Ethereum compatibility layer. In affected versions the truncation done when converting between E... |
| CVE-2022-34598 | CRITICAL | 9.8 | 5.3% | Jul 6, 2022 | The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary ... |
| CVE-2022-34597 | CRITICAL | 9.8 | 2.5% | Jul 6, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting. |
| CVE-2022-34596 | CRITICAL | 9.8 | 2.6% | Jul 6, 2022 | Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSett... |
| CVE-2022-34595 | CRITICAL | 9.8 | 2.6% | Jul 6, 2022 | Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status. |
| CVE-2022-26348 | MEDIUM | 5.5 | 0.3% | Jul 6, 2022 | Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The Wi... |
| CVE-2022-26078 | HIGH | 7.5 | 0.8% | Jul 6, 2022 | Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP ad... |
| CVE-2022-33738 | HIGH | 7.5 | 0.8% | Jul 6, 2022 | OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal |
| CVE-2022-33737 | HIGH | 7.5 | 0.7% | Jul 6, 2022 | The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now