2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1988MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository neorazorx/facturascripts prior to 2022.09.
CVE-2022-1987HIGH8.1Buffer Over-read in GitHub repository bfabiszewski/libmobi prior to 0.11.
CVE-2022-32271CRITICAL9.6In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL ...
CVE-2022-32270CRITICAL9.8In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Trave...
CVE-2022-32269CRITICAL9.8In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (display...
CVE-2022-32268HIGH8.8StarWind SAN and NAS v0.2 build 1914 allow remote code execution. A flaw was found in REST API in StarWind Stack. REST c...
CVE-2022-32265MEDIUM5.3qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding.
CVE-2022-29767MEDIUM6.5adbyby v2.7 allows external users to make connections via port 8118. This can cause a program logic error and lead to a ...
CVE-2022-30238HIGH8.8A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when...
CVE-2022-30237HIGH7.5A CWE-311: Missing Encryption of Sensitive Data vulnerability exists that could allow authentication credentials to be r...
CVE-2022-30236HIGH8.2A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow unauthorized access when an...
CVE-2022-30235CRITICAL9.8A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow unauthorized ...
CVE-2022-30234CRITICAL9.8A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root l...
CVE-2022-30233MEDIUM6.5A CWE-20: Improper Input Validation vulnerability exists that could allow the product to be maliciously manipulated when...
CVE-2022-30232HIGH8.8A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attack...
CVE-2022-29594HIGH7.8eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM.
CVE-2022-31463HIGH7.1Owl Labs Meeting Owl 5.2.0.15 does not require a password for Bluetooth commands, because only client-side authenticatio...
CVE-2022-31462HIGH8.8Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial nu...
CVE-2022-31461MEDIUM6.5Owl Labs Meeting Owl 5.2.0.15 allows attackers to deactivate the passcode protection mechanism via a certain c 11 messag...
CVE-2022-31460HIGH7.4Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded hoothoot credentials via a cer...
CVE-2022-31459MEDIUM6.5Owl Labs Meeting Owl 5.2.0.15 allows attackers to retrieve the passcode hash via a certain c 10 value over Bluetooth.
CVE-2022-32250HIGH7.8net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces...
CVE-2022-29718MEDIUM6.1Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this ...
CVE-2022-29085MEDIUM6.7Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulne...
CVE-2022-29084CRITICAL9.8Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication atte...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now