2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1110 | MEDIUM | 5.5 | 0.2% | May 18, 2022 | A buffer overflow vulnerability in Lenovo Smart Standby Driver prior to version 4.1.50.0 could allow a local attacker to... |
| CVE-2022-30065 | HIGH | 7.8 | 1.2% | May 18, 2022 | A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a... |
| CVE-2022-29518 | HIGH | 7 | 0.2% | May 18, 2022 | Screen Creator Advance2, HMI GC-A2 series, and Real time remote monitoring and control tool Screen Creator Advance2 vers... |
| CVE-2022-29516 | CRITICAL | 9.8 | 1.9% | May 18, 2022 | The web console of FUJITSU Network IPCOM series (IPCOM EX2 IN(3200, 3500), IPCOM EX2 LB(1100, 3200, 3500), IPCOM EX2 SC(... |
| CVE-2022-28717 | MEDIUM | 4.8 | 0.5% | May 18, 2022 | Cross-site scripting vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions, WATCH BOOT l... |
| CVE-2022-27632 | HIGH | 8.8 | 0.5% | May 18, 2022 | Cross-site request forgery (CSRF) vulnerability in Rebooter(WATCH BOOT nino RPC-M2C [End of Sale] all firmware versions,... |
| CVE-2022-1795 | CRITICAL | 9.8 | 1.0% | May 18, 2022 | Use After Free in GitHub repository gpac/gpac prior to v2.1.0-DEV. |
| CVE-2022-1782 | MEDIUM | 6.1 | 0.9% | May 18, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository erudika/para prior to v1.45.11. |
| CVE-2022-23068 | MEDIUM | 5.4 | 0.6% | May 18, 2022 | ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside t... |
| CVE-2022-23067 | HIGH | 8.8 | 1.2% | May 18, 2022 | ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If... |
| CVE-2022-1727 | HIGH | 8.8 | 1.4% | May 18, 2022 | Improper Input Validation in GitHub repository jgraph/drawio prior to 18.0.6. |
| CVE-2022-1432 | MEDIUM | 6.4 | 1.2% | May 18, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0. |
| CVE-2022-1430 | HIGH | 7.5 | 1.3% | May 18, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0. |
| CVE-2022-29646 | MEDIUM | 5.3 | 0.8% | May 18, 2022 | An access control issue in TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 allows attackers to obtai... |
| CVE-2022-29645 | CRITICAL | 9.8 | 1.3% | May 18, 2022 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for... |
| CVE-2022-29644 | CRITICAL | 9.8 | 1.5% | May 18, 2022 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a hard coded password for... |
| CVE-2022-29643 | HIGH | 7.5 | 1.1% | May 18, 2022 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the ... |
| CVE-2022-29642 | HIGH | 7.5 | 1.1% | May 18, 2022 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the ... |
| CVE-2022-29641 | HIGH | 7.5 | 1.3% | May 18, 2022 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the ... |
| CVE-2022-29640 | HIGH | 7.5 | 1.1% | May 18, 2022 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the ... |
| CVE-2022-29639 | HIGH | 8.1 | 1.8% | May 18, 2022 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a command injection vulne... |
| CVE-2022-29638 | HIGH | 7.5 | 1.1% | May 18, 2022 | TOTOLINK A3100R V4.1.2cu.5050_B20200504 and V4.1.2cu.5247_B20211129 were discovered to contain a stack overflow via the ... |
| CVE-2022-28958 | — | — | — | May 18, 2022 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2022-28956 | CRITICAL | 9.8 | 22.4% | May 18, 2022 | An issue in the getcfg.php component of D-Link DIR816L_FW206b01 allows attackers to access the device via a crafted payl... |
| CVE-2022-28955 | HIGH | 7.5 | 38.3% | May 18, 2022 | An access control issue in D-Link DIR816L_FW206b01 allows unauthenticated attackers to access folders folder_view.php an... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now