2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2282 | — | — | — | Jul 1, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. Al... |
| CVE-2022-33103 | HIGH | 7.8 | 0.4% | Jul 1, 2022 | Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir(... |
| CVE-2022-33099 | HIGH | 7.5 | 2.1% | Jul 1, 2022 | An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error o... |
| CVE-2022-2264 | HIGH | 7.8 | 1.0% | Jul 1, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0. |
| CVE-2022-34894 | MEDIUM | 5.3 | 0.5% | Jul 1, 2022 | In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services |
| CVE-2022-2280 | MEDIUM | 5.4 | 0.5% | Jul 1, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19. |
| CVE-2022-2279 | MEDIUM | 5.5 | 0.5% | Jul 1, 2022 | NULL Pointer Dereference in GitHub repository bfabiszewski/libmobi prior to 0.11. |
| CVE-2022-2274 | CRITICAL | 9.8 | 36.5% | Jul 1, 2022 | The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA i... |
| CVE-2022-32988 | MEDIUM | 5.4 | 0.5% | Jul 1, 2022 | Cross Site Scripting (XSS) vulnerability in router Asus DSL-N14U-B1 1.1.2.3_805 via the "*list" parameters (e.g. filter_... |
| CVE-2022-32295 | CRITICAL | 9.8 | 1.1% | Jul 1, 2022 | On Ampere Altra and AltraMax devices before SRP 1.09, the Altra reference design of UEFI accesses allows insecure access... |
| CVE-2022-27904 | HIGH | 7 | 0.2% | Jul 1, 2022 | Automox Agent for macOS before version 39 was vulnerable to a time-of-check/time-of-use (TOCTOU) race-condition attack d... |
| CVE-2022-33087 | HIGH | 7.5 | 1.4% | Jun 30, 2022 | A stack overflow in the function DM_ In fillobjbystr() of TP-Link Archer C50&A5(US)_V5_200407 allows attackers to cause ... |
| CVE-2022-33085 | HIGH | 7.2 | 1.5% | Jun 30, 2022 | ESPCMS P8 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the fetch_filename fu... |
| CVE-2022-33082 | HIGH | 7.5 | 1.4% | Jun 30, 2022 | An issue in the AST parser (ast/compile.go) of Open Policy Agent v0.10.2 allows attackers to cause a Denial of Service (... |
| CVE-2022-31115 | HIGH | 8.8 | 1.3% | Jun 30, 2022 | opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML... |
| CVE-2022-2257 | HIGH | 7.8 | 1.1% | Jun 30, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0. |
| CVE-2022-23725 | MEDIUM | 5.5 | 0.2% | Jun 30, 2022 | PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensit... |
| CVE-2022-23720 | HIGH | 8.2 | 0.2% | Jun 30, 2022 | PingID Windows Login prior to 2.8 does not alert or halt operation if it has been provisioned with the full permissions ... |
| CVE-2022-23719 | MEDIUM | 6.4 | 0.3% | Jun 30, 2022 | PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security... |
| CVE-2022-23718 | HIGH | 8.1 | 1.6% | Jun 30, 2022 | PingID Windows Login prior to 2.8 uses known vulnerable components that can lead to remote code execution. An attacker c... |
| CVE-2022-23717 | MEDIUM | 5.5 | 0.2% | Jun 30, 2022 | PingID Windows Login prior to 2.8 is vulnerable to a denial of service condition on local machines when combined with us... |
| CVE-2022-33329 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.... |
| CVE-2022-33328 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.... |
| CVE-2022-33327 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.... |
| CVE-2022-33326 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now