2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-21767HIGH8.8In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation...
CVE-2022-21766MEDIUM6.7In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p...
CVE-2022-21765MEDIUM6.7In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p...
CVE-2022-21764MEDIUM5.5In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to loc...
CVE-2022-21763MEDIUM5.5In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to loc...
CVE-2022-21744CRITICAL9.8In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code ex...
CVE-2022-20083CRITICAL9.8In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code...
CVE-2022-20082HIGH7In GPU, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wit...
CVE-2022-33980CRITICAL9.8Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expand...
CVE-2022-28935HIGH7.2Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, T...
CVE-2022-24141MEDIUM5.4The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacke...
CVE-2022-24140MEDIUM6.6IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP ...
CVE-2022-24139HIGH7.8In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with ...
CVE-2022-24138HIGH7.8IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramD...
CVE-2022-32386CRITICAL9.8Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan.
CVE-2022-32385CRITICAL9.8Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote).
CVE-2022-32383CRITICAL9.8Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the AdvSetMacMtuWan function.
CVE-2022-32290MEDIUM4.3The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivi...
CVE-2022-30591HIGH7.5quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in...
CVE-2022-35230MEDIUM5.4An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to othe...
CVE-2022-35229MEDIUM5.4An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to o...
CVE-2022-32533CRITICAL9.8Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including X...
CVE-2022-22681HIGH7.5Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote a...
CVE-2022-34972CRITICAL9.8So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_v...
CVE-2022-32413CRITICAL9.8An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now