2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29483HIGH7.8Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with...
CVE-2022-28945CRITICAL9.8An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.
CVE-2022-28799HIGH8.8The TikTok application before 23.7.3 for Android allows account takeover. A crafted URL (unvalidated deeplink) can force...
CVE-2022-28702MEDIUM5.5Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with...
CVE-2022-28690HIGH7.8The affected product is vulnerable to an out-of-bounds write via uninitialized pointer, which may allow an attacker to e...
CVE-2022-28605CRITICAL9.8Hardcoded admin token in SoundBar apps in Linkplay SDK 1.00 allows remote attackers to gain admin privilege access in li...
CVE-2022-27782HIGH7.5libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should ha...
CVE-2022-27781HIGH7.5libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's c...
CVE-2022-27780HIGH7.5The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, ma...
CVE-2022-27779MEDIUM5.3libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.cu...
CVE-2022-27778HIGH8.1A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used...
CVE-2022-27776MEDIUM6.5A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header ...
CVE-2022-27775HIGH7.5An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address tha...
CVE-2022-27774MEDIUM5.7An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that co...
CVE-2022-27184HIGH7.8The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.
CVE-2022-26978MEDIUM6.1Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checkl...
CVE-2022-26977MEDIUM6.1Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil...
CVE-2022-26976MEDIUM5.4Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil...
CVE-2022-26975HIGH7.5Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files wit...
CVE-2022-26974MEDIUM6.1Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload...
CVE-2022-26973MEDIUM5.3Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil...
CVE-2022-26972MEDIUM6.1Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bi...
CVE-2022-26971MEDIUM5.3Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license fil...
CVE-2022-26491MEDIUM5.9An issue was discovered in Pidgin before 2.14.9. A remote attacker who can spoof DNS responses can redirect a client con...
CVE-2022-25237CRITICAL9.8Bonita Web 2021.2 is affected by a authentication/authorization bypass vulnerability due to an overly broad exclude patt...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now