2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24967 | MEDIUM | 5.4 | 0.6% | Jun 2, 2022 | Black Rainbow NIMBUS before 3.7.0 allows stored Cross-site Scripting (XSS). |
| CVE-2022-24702 | CRITICAL | 9.8 | 5.6% | Jun 2, 2022 | An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to ac... |
| CVE-2022-24701 | HIGH | 7.8 | 0.5% | Jun 2, 2022 | An issue was discovered in WinAPRS 2.9.0. A buffer overflow in national.txt processing allows a local attacker to cause ... |
| CVE-2022-24700 | HIGH | 7.5 | 1.7% | Jun 2, 2022 | An issue was discovered in WinAPRS 2.9.0. A buffer overflow in DIGI address processing for VHF KISS packets allows a rem... |
| CVE-2022-24581 | HIGH | 7.5 | 1.1% | Jun 2, 2022 | ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an exte... |
| CVE-2022-24241 | HIGH | 7.5 | 1.1% | Jun 2, 2022 | ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the t... |
| CVE-2022-24240 | CRITICAL | 9.8 | 1.1% | Jun 2, 2022 | ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in shows... |
| CVE-2022-24239 | CRITICAL | 9.8 | 1.3% | Jun 2, 2022 | ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp. |
| CVE-2022-24238 | MEDIUM | 6.1 | 0.7% | Jun 2, 2022 | ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 par... |
| CVE-2022-23237 | MEDIUM | 6.1 | 0.6% | Jun 2, 2022 | E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks... |
| CVE-2022-23236 | MEDIUM | 4.4 | 0.2% | Jun 2, 2022 | E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext with... |
| CVE-2022-22767 | HIGH | 8.8 | 0.4% | Jun 2, 2022 | Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentia... |
| CVE-2022-1968 | HIGH | 7.8 | 1.4% | Jun 2, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-1949 | HIGH | 7.5 | 1.4% | Jun 2, 2022 | An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect r... |
| CVE-2022-1943 | HIGH | 7.8 | 0.3% | Jun 2, 2022 | A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers s... |
| CVE-2022-1929 | HIGH | 7.5 | 0.6% | Jun 2, 2022 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacke... |
| CVE-2022-1797 | HIGH | 8.6 | 1.9% | Jun 2, 2022 | A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition ... |
| CVE-2022-1789 | MEDIUM | 6.8 | 0.3% | Jun 2, 2022 | With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed wit... |
| CVE-2022-1786 | HIGH | 7.8 | 1.0% | Jun 2, 2022 | A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SE... |
| CVE-2022-1661 | HIGH | 7.5 | 15.1% | Jun 2, 2022 | The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating s... |
| CVE-2022-1660 | CRITICAL | 9.8 | 16.0% | Jun 2, 2022 | The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication... |
| CVE-2022-1652 | HIGH | 7.8 | 0.5% | Jun 2, 2022 | Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-fre... |
| CVE-2022-1462 | MEDIUM | 6.3 | 0.3% | Jun 2, 2022 | An out-of-bounds read flaw was found in the Linux kernel’s TeleTYpe subsystem. The issue occurs in how a user triggers a... |
| CVE-2022-1419 | HIGH | 7.8 | 0.3% | Jun 2, 2022 | The root cause of this vulnerability is that the ioctl$DRM_IOCTL_MODE_DESTROY_DUMB can decrease refcount of *drm_vgem_ge... |
| CVE-2022-1215 | HIGH | 7.8 | 0.4% | Jun 2, 2022 | A format string vulnerability was found in libinput |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now