2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35927 | CRITICAL | 9.8 | 1.6% | Aug 4, 2022 | Contiki-NG is an open-source, cross-platform operating system for IoT devices. In the RPL-Classic routing protocol imple... |
| CVE-2022-35143 | CRITICAL | 9.8 | 1.3% | Aug 4, 2022 | Renato v0.17.0 employs weak password complexity requirements, allowing attackers to crack user passwords via brute-force... |
| CVE-2022-35929 | CRITICAL | 9.8 | 0.5% | Aug 4, 2022 | cosign is a container signing and verification utility. In versions prior to 1.10.1 cosign can report a false positive i... |
| CVE-2022-34993 | CRITICAL | 9.8 | 0.9% | Aug 4, 2022 | Totolink A3600R_Firmware V4.1.2cu.5182_B20201102 contains a hard code password for root in /etc/shadow.sample. |
| CVE-2022-34970 | CRITICAL | 9.8 | 2.8% | Aug 4, 2022 | Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h. On successful exploitati... |
| CVE-2022-35728 | CRITICAL | 9.8 | 0.6% | Aug 4, 2022 | In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and a... |
| CVE-2022-35243 | CRITICAL | 9.1 | 0.6% | Aug 4, 2022 | In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.5.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when ... |
| CVE-2022-34865 | CRITICAL | 9.1 | 0.4% | Aug 4, 2022 | In BIG-IP Versions 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, Traffic Intelligence feeds,... |
| CVE-2022-31132 | CRITICAL | 9.8 | 0.6% | Aug 4, 2022 | Nextcloud Mail is an email application for the nextcloud personal cloud product. Affected versions shipped with a CSS mi... |
| CVE-2022-25168 | CRITICAL | 9.8 | 3.3% | Aug 4, 2022 | Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An ... |
| CVE-2022-2656 | CRITICAL | 9.8 | 0.6% | Aug 4, 2022 | A vulnerability classified as critical has been found in SourceCodester Multi Language Hotel Management Software. Affect... |
| CVE-2022-32965 | CRITICAL | 9.8 | 1.1% | Aug 4, 2022 | OMICARD EDM has a hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized ... |
| CVE-2022-32964 | CRITICAL | 9.8 | 1.1% | Aug 4, 2022 | OMICARD EDM’s API function has insufficient validation for user input. An unauthenticated remote attacker can inject arb... |
| CVE-2022-2651 | CRITICAL | 9.8 | 11.4% | Aug 4, 2022 | Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5. |
| CVE-2022-2648 | CRITICAL | 9.8 | 0.7% | Aug 4, 2022 | A vulnerability was found in SourceCodester Multi Language Hotel Management Software. It has been rated as critical. Thi... |
| CVE-2022-2647 | CRITICAL | 9.8 | 0.7% | Aug 4, 2022 | A vulnerability was found in jeecg-boot. It has been declared as critical. This vulnerability affects unknown code of th... |
| CVE-2022-2644 | CRITICAL | 9.8 | 0.7% | Aug 4, 2022 | A vulnerability was found in SourceCodester Online Admission System and classified as critical. This issue affects some ... |
| CVE-2022-2643 | CRITICAL | 9.8 | 0.7% | Aug 4, 2022 | A vulnerability has been found in SourceCodester Online Admission System and classified as critical. This vulnerability ... |
| CVE-2022-35161 | CRITICAL | 9.8 | 0.9% | Aug 3, 2022 | GVRET Stable Release as of Aug 15, 2015 was discovered to contain a buffer overflow via the handleConfigCmd function at ... |
| CVE-2022-35866 | CRITICAL | 9.8 | 3.1% | Aug 3, 2022 | This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Reco... |
| CVE-2022-35865 | CRITICAL | 9.8 | 1.4% | Aug 3, 2022 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.... |
| CVE-2022-2272 | CRITICAL | 9.8 | 2.3% | Aug 3, 2022 | This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4... |
| CVE-2022-35620 | CRITICAL | 9.8 | 31.3% | Aug 3, 2022 | D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the funct... |
| CVE-2022-35619 | CRITICAL | 9.8 | 2.0% | Aug 3, 2022 | D-LINK DIR-818LW A1:DIR818L_FW105b01 was discovered to contain a remote code execution (RCE) vulnerability via the funct... |
| CVE-2022-34974 | CRITICAL | 9.8 | 23.0% | Aug 3, 2022 | D-Link DIR810LA1_FW102B22 was discovered to contain a command injection vulnerability via the Ping_addr function. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now