2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29483 | HIGH | 7.8 | 0.3% | Jun 2, 2022 | Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with... |
| CVE-2022-28945 | CRITICAL | 9.8 | 2.0% | Jun 2, 2022 | An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file. |
| CVE-2022-28799 | HIGH | 8.8 | 15.5% | Jun 2, 2022 | The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force... |
| CVE-2022-28702 | MEDIUM | 5.5 | 0.3% | Jun 2, 2022 | Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with... |
| CVE-2022-28690 | HIGH | 7.8 | 0.8% | Jun 2, 2022 | The affected product is vulnerable to an out-of-bounds write via uninitialized pointer, which may allow an attacker to e... |
| CVE-2022-28605 | CRITICAL | 9.8 | 1.8% | Jun 2, 2022 | Hardcoded admin token in SoundBar apps in Linkplay SDK 1.00 allows remote attackers to gain admin privilege access in li... |
| CVE-2022-27782 | HIGH | 7.5 | 2.6% | Jun 2, 2022 | libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should ha... |
| CVE-2022-27781 | HIGH | 7.5 | 2.4% | Jun 2, 2022 | libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's c... |
| CVE-2022-27780 | HIGH | 7.5 | 2.2% | Jun 2, 2022 | The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, ma... |
| CVE-2022-27779 | MEDIUM | 5.3 | 2.4% | Jun 2, 2022 | libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.cu... |
| CVE-2022-27778 | HIGH | 8.1 | 3.5% | Jun 2, 2022 | A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used... |
| CVE-2022-27776 | MEDIUM | 6.5 | 3.4% | Jun 2, 2022 | A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header ... |
| CVE-2022-27775 | HIGH | 7.5 | 2.8% | Jun 2, 2022 | An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address tha... |
| CVE-2022-27774 | MEDIUM | 5.7 | 1.6% | Jun 2, 2022 | An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that co... |
| CVE-2022-27184 | HIGH | 7.8 | 0.8% | Jun 2, 2022 | The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code. |
| CVE-2022-26978 | MEDIUM | 6.1 | 0.5% | Jun 2, 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checkl... |
| CVE-2022-26977 | MEDIUM | 6.1 | 0.5% | Jun 2, 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil... |
| CVE-2022-26976 | MEDIUM | 5.4 | 0.4% | Jun 2, 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil... |
| CVE-2022-26975 | HIGH | 7.5 | 0.9% | Jun 2, 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files wit... |
| CVE-2022-26974 | MEDIUM | 6.1 | 0.5% | Jun 2, 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload... |
| CVE-2022-26973 | MEDIUM | 5.3 | 0.7% | Jun 2, 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil... |
| CVE-2022-26972 | MEDIUM | 6.1 | 0.5% | Jun 2, 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bi... |
| CVE-2022-26971 | MEDIUM | 5.3 | 0.7% | Jun 2, 2022 | Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil... |
| CVE-2022-26491 | MEDIUM | 5.9 | 2.4% | Jun 2, 2022 | An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client con... |
| CVE-2022-25237 | CRITICAL | 9.8 | 56.2% | Jun 2, 2022 | Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude patt... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now