2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1747MEDIUM4.6The authentication mechanism used by voters to activate a voting session on the tested version of Dominion Voting System...
CVE-2022-1746HIGH7.6The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Syste...
CVE-2022-1745MEDIUM6.8The authentication mechanism used by technicians on the tested version of Dominion Voting Systems ImageCast X is suscept...
CVE-2022-1744MEDIUM6.8Applications on the tested version of Dominion Voting Systems ImageCast X can execute code with elevated privileges by e...
CVE-2022-1743MEDIUM6.8The tested version of Dominion Voting System ImageCast X can be manipulated to cause arbitrary code execution by special...
CVE-2022-1742MEDIUM6.8The tested version of Dominion Voting Systems ImageCast X allows for rebooting into Android Safe Mode, which allows an a...
CVE-2022-1741MEDIUM6.8The tested version of Dominion Voting Systems ImageCast X has a Terminal Emulator application which could be leveraged b...
CVE-2022-1740MEDIUM4.6The tested version of Dominion Voting Systems ImageCast X’s on-screen application hash display feature, audit log export...
CVE-2022-1739MEDIUM6.8The tested version of Dominion Voting Systems ImageCast X does not validate application signatures to a trusted root cer...
CVE-2022-1668CRITICAL9.8Weak default root user credentials allow remote attackers to easily obtain OS superuser privileges over the open TCP por...
CVE-2022-1667HIGH7.5Client-side JavaScript controls may be bypassed by directly running a JS function to reboot the PLC (e.g., from the brow...
CVE-2022-1666MEDIUM6.5The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was us...
CVE-2022-1524MEDIUM5.9LRM version 2.4 and lower does not implement TLS encryption. A malicious actor can MITM attack sensitive data in-transit...
CVE-2022-1521CRITICAL9.1LRM does not implement authentication or authorization by default. A malicious actor can inject, replay, modify, and/or ...
CVE-2022-1519CRITICAL9.8LRM does not restrict the types of files that can be uploaded to the affected product. A malicious actor can upload any ...
CVE-2022-1518CRITICAL9.8LRM contains a directory traversal vulnerability that can allow a malicious actor to upload outside the intended directo...
CVE-2022-1517CRITICAL9.8LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operati...
CVE-2022-32990MEDIUM5.5An issue in gimp_layer_invalidate_boundary of GNOME GIMP 2.10.30 allows attackers to trigger an unhandled exception via ...
CVE-2022-32530HIGH7.8A CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms, ...
CVE-2022-32143HIGH8.8In multiple CODESYS products, file download and upload function allows access to internal files in the working directory...
CVE-2022-32142HIGH8.1Multiple CODESYS Products are prone to a out-of bounds read or write access. A low privileged remote attacker may craft ...
CVE-2022-32141MEDIUM6.5Multiple CODESYS Products are prone to a buffer over read. A low privileged remote attacker may craft a request with an ...
CVE-2022-32140MEDIUM6.5Multiple CODESYS products are affected to a buffer overflow.A low privileged remote attacker may craft a request, which ...
CVE-2022-32139MEDIUM6.5In multiple CODESYS products, a low privileged remote attacker may craft a request, which cause an out-of-bounds read, r...
CVE-2022-32138HIGH8.8In multiple CODESYS products, a remote attacker may craft a request which may cause an unexpected sign extension, result...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now