2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28339HIGH7.8Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnera...
CVE-2022-46283Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
CVE-2022-41545MEDIUM6.4The administrative web interface of a Netgear C7800 Router running firmware version 6.01.07 (and possibly others) authen...
CVE-2022-28693MEDIUM4.7Unprotected alternative channel of return branch target prediction in some Intel(R) Processors may allow an authorized u...
CVE-2022-26083HIGH7.5Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allo...
CVE-2022-31631CRITICAL9.1In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote u...
CVE-2022-37660MEDIUM6.5In hostapd 2.10 and earlier, the PKEX code remains active even after a successful PKEX association. An attacker that suc...
CVE-2022-3180CRITICAL9.8The WPGateway Plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.5. This all...
CVE-2022-35202MEDIUM5.1A security issue in Sitevision version 10.3.1 and older allows a remote attacker, in certain (non-default) scenarios, to...
CVE-2022-2283Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2022-26389HIGH7.7An improper access control vulnerability may allow privilege escalation.This issue affects:  * ELI 380 Resting Elect...
CVE-2022-26388MEDIUM6.4A use of hard-coded password vulnerability may allow authentication abuse.This issue affects ELI 380 Resting Electrocard...
CVE-2022-40916CRITICAL9.8Tiny File Manager v2.4.7 and below is vulnerable to session fixation.
CVE-2022-40490MEDIUM4.8Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerabil...
CVE-2022-31764HIGH8.5The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL ...
CVE-2022-1736CRITICAL9.8Ubuntu's configuration of gnome-control-center allowed Remote Desktop Sharing to be enabled by default.
CVE-2022-28653HIGH7.5Users can consume unlimited disk space in /var/crash
CVE-2022-43916CRITICAL9.1IBM App Connect Enterprise Certified Container 7.1, 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11....
CVE-2022-3365CRITICAL9.8Due to reliance on a trivial substitution cipher, sent in cleartext, and the reliance on a default password when the use...
CVE-2022-31749MEDIUM6.5An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12....
CVE-2022-4975HIGH8.9A flaw was found in the Red Hat Advanced Cluster Security (RHACS) portal. When rendering a table view in the portal, for...
CVE-2022-49043HIGH7.8xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.
CVE-2022-47090HIGH7.8GPAC MP4box 2.1-DEV-rev574-g9d5bb184b contains a buffer overflow in gf_vvc_read_pps_bs_internal function of media_tools/...
CVE-2022-23439MEDIUM6.1A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison w...
CVE-2022-20128Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now