2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-21767 | HIGH | 8.8 | 0.3% | Jul 6, 2022 | In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation... |
| CVE-2022-21766 | MEDIUM | 6.7 | 0.1% | Jul 6, 2022 | In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p... |
| CVE-2022-21765 | MEDIUM | 6.7 | 0.1% | Jul 6, 2022 | In CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p... |
| CVE-2022-21764 | MEDIUM | 5.5 | 0.1% | Jul 6, 2022 | In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to loc... |
| CVE-2022-21763 | MEDIUM | 5.5 | 0.1% | Jul 6, 2022 | In telecom service, there is a possible information disclosure due to a missing permission check. This could lead to loc... |
| CVE-2022-21744 | CRITICAL | 9.8 | 2.6% | Jul 6, 2022 | In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code ex... |
| CVE-2022-20083 | CRITICAL | 9.8 | 2.2% | Jul 6, 2022 | In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code... |
| CVE-2022-20082 | HIGH | 7 | 0.1% | Jul 6, 2022 | In GPU, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wit... |
| CVE-2022-33980 | CRITICAL | 9.8 | 34.8% | Jul 6, 2022 | Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expand... |
| CVE-2022-28935 | HIGH | 7.2 | 3.0% | Jul 6, 2022 | Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, T... |
| CVE-2022-24141 | MEDIUM | 5.4 | 0.7% | Jul 6, 2022 | The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacke... |
| CVE-2022-24140 | MEDIUM | 6.6 | 1.0% | Jul 6, 2022 | IOBit Advanced System Care 15, iTop Screen Recorder 2.1, iTop VPN 3.2, Driver Booster 9, and iTop Screenshot sends HTTP ... |
| CVE-2022-24139 | HIGH | 7.8 | 0.4% | Jul 6, 2022 | In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with ... |
| CVE-2022-24138 | HIGH | 7.8 | 0.5% | Jul 6, 2022 | IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramD... |
| CVE-2022-32386 | CRITICAL | 9.8 | 11.2% | Jul 6, 2022 | Tenda AC23 v16.03.07.44 was discovered to contain a buffer overflow via fromAdvSetMacMtuWan. |
| CVE-2022-32385 | CRITICAL | 9.8 | 2.4% | Jul 6, 2022 | Tenda AC23 v16.03.07.44 is vulnerable to Stack Overflow that will allow for the execution of arbitrary code (remote). |
| CVE-2022-32383 | CRITICAL | 9.8 | 1.2% | Jul 6, 2022 | Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the AdvSetMacMtuWan function. |
| CVE-2022-32290 | MEDIUM | 4.3 | 0.2% | Jul 6, 2022 | The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivi... |
| CVE-2022-30591 | HIGH | 7.5 | 2.4% | Jul 6, 2022 | quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in... |
| CVE-2022-35230 | MEDIUM | 5.4 | 0.6% | Jul 6, 2022 | An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to othe... |
| CVE-2022-35229 | MEDIUM | 5.4 | 0.6% | Jul 6, 2022 | An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to o... |
| CVE-2022-32533 | CRITICAL | 9.8 | 3.2% | Jul 6, 2022 | Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including X... |
| CVE-2022-22681 | HIGH | 7.5 | 0.9% | Jul 6, 2022 | Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote a... |
| CVE-2022-34972 | CRITICAL | 9.8 | 1.3% | Jul 5, 2022 | So Filter Shop v3.x was discovered to contain multiple blind SQL injection vulnerabilities via the att_value_id , manu_v... |
| CVE-2022-32413 | CRITICAL | 9.8 | 1.5% | Jul 5, 2022 | An arbitrary file upload vulnerability in Dice v4.2.0 allows attackers to execute arbitrary code via a crafted file. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now