2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-20813MEDIUM5.9Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TeleP...
CVE-2022-20812MEDIUM6.5Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TeleP...
CVE-2022-20808MEDIUM6.5A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to c...
CVE-2022-20800MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unifie...
CVE-2022-20791MEDIUM6.5A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Comm...
CVE-2022-20768MEDIUM4.9A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could all...
CVE-2022-20752MEDIUM5.3A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Manag...
CVE-2022-33047CRITICAL9.8OTFCC v0.10.4 was discovered to contain a heap buffer overflow after free via otfccbuild.c.
CVE-2022-2318MEDIUM5.5There are use-after-free vulnerabilities caused by timer handler in net/rose/rose_timer.c of linux that allow attackers ...
CVE-2022-2316MEDIUM5.4HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the render...
CVE-2022-31131MEDIUM4.3Nextcloud mail is a Mail app for the Nextcloud home server product. Versions of Nextcloud mail prior to 1.12.2 were foun...
CVE-2022-31129HIGH7.5moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of mo...
CVE-2022-31127MEDIUM6.1NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromis...
CVE-2022-31126CRITICAL9.8Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in R...
CVE-2022-31125CRITICAL9.8Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in R...
CVE-2022-31124MEDIUM6.5openssh_key_parser is an open source Python package providing utilities to parse and pack OpenSSH private and public key...
CVE-2022-31111MEDIUM5.3Frontier is Substrate's Ethereum compatibility layer. In affected versions the truncation done when converting between E...
CVE-2022-34598CRITICAL9.8The udpserver in H3C Magic R100 V200R004 and V100R005 has the 9034 port opened, allowing attackers to execute arbitrary ...
CVE-2022-34597CRITICAL9.8Tenda AX1806 v1.0.0.1 was discovered to contain a command injection vulnerability via the function WanParameterSetting.
CVE-2022-34596CRITICAL9.8Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function WanParameterSett...
CVE-2022-34595CRITICAL9.8Tenda AX1803 v1.0.0.1_2890 was discovered to contain a command injection vulnerability via the function setipv6status.
CVE-2022-26348MEDIUM5.5Command Centre Server is vulnerable to SQL Injection via Windows Registry settings for date fields on the server. The Wi...
CVE-2022-26078HIGH7.5Gallagher Controller 6000 is vulnerable to a Denial of Service attack via conflicting ARP packets with a duplicate IP ad...
CVE-2022-33738HIGH7.5OpenVPN Access Server before 2.11 uses a weak random generator used to create user session token for the web portal
CVE-2022-33737HIGH7.5The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11....

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now