2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28005 | CRITICAL | 9.8 | 6.2% | May 6, 2022 | An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticate... |
| CVE-2022-28973 | HIGH | 7.5 | 1.1% | May 6, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the function fromAdvSetMacM... |
| CVE-2022-28972 | HIGH | 7.5 | 1.1% | May 6, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the function form_fast_se... |
| CVE-2022-28971 | HIGH | 7.5 | 1.1% | May 6, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function fromSetIpMacBind... |
| CVE-2022-28970 | HIGH | 7.5 | 1.1% | May 6, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow via the mac parameter in the function GetParentControlIn... |
| CVE-2022-28969 | HIGH | 7.5 | 1.1% | May 6, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWif... |
| CVE-2022-24823 | MEDIUM | 5.5 | 1.0% | May 6, 2022 | Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http... |
| CVE-2022-30295 | MEDIUM | 6.5 | 11.3% | May 6, 2022 | uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache pois... |
| CVE-2022-30294 | — | — | — | May 6, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-30293. Reason: This candidate is a duplicate of ... |
| CVE-2022-30293 | HIGH | 7.5 | 2.0% | May 6, 2022 | In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setC... |
| CVE-2022-24878 | MEDIUM | 6.5 | 0.9% | May 6, 2022 | Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller v... |
| CVE-2022-24877 | HIGH | 8.8 | 1.1% | May 6, 2022 | Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller v... |
| CVE-2022-29171 | HIGH | 7.2 | 1.2% | May 6, 2022 | Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote ... |
| CVE-2022-29164 | HIGH | 7.1 | 0.8% | May 6, 2022 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. In affe... |
| CVE-2022-29161 | CRITICAL | 9.8 | 0.4% | May 6, 2022 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypt... |
| CVE-2022-24903 | HIGH | 8.1 | 3.6% | May 6, 2022 | Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overfl... |
| CVE-2022-24902 | MEDIUM | 4.3 | 0.5% | May 6, 2022 | TkVideoplayer is a simple library to play video files in tkinter. Uncontrolled memory consumption in versions of TKVideo... |
| CVE-2022-24899 | MEDIUM | 6.1 | 3.7% | May 6, 2022 | Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In v... |
| CVE-2022-24884 | HIGH | 7.5 | 1.0% | May 6, 2022 | ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` doe... |
| CVE-2022-24817 | CRITICAL | 9.9 | 1.0% | May 6, 2022 | Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, he... |
| CVE-2022-29535 | CRITICAL | 9.8 | 93.4% | May 5, 2022 | Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports. |
| CVE-2022-29175 | — | — | — | May 5, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: This candidate was withdrawn. Further inves... |
| CVE-2022-29173 | HIGH | 8.8 | 0.5% | May 5, 2022 | go-tuf is a Go implementation of The Update Framework (TUF). go-tuf does not correctly implement the client workflow for... |
| CVE-2022-29172 | MEDIUM | 6.1 | 0.6% | May 5, 2022 | Auth0 is an authentication broker that supports both social and enterprise identity providers, including Active Director... |
| CVE-2022-29167 | HIGH | 7.5 | 1.0% | May 5, 2022 | Hawk is an HTTP authentication scheme providing mechanisms for making authenticated HTTP requests with partial cryptogra... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now