2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28005CRITICAL9.8An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticate...
CVE-2022-28973HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the function fromAdvSetMacM...
CVE-2022-28972HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the function form_fast_se...
CVE-2022-28971HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function fromSetIpMacBind...
CVE-2022-28970HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow via the mac parameter in the function GetParentControlIn...
CVE-2022-28969HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWif...
CVE-2022-24823MEDIUM5.5Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http...
CVE-2022-30295MEDIUM6.5uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache pois...
CVE-2022-30294Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-30293. Reason: This candidate is a duplicate of ...
CVE-2022-30293HIGH7.5In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setC...
CVE-2022-24878MEDIUM6.5Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller v...
CVE-2022-24877HIGH8.8Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller v...
CVE-2022-29171HIGH7.2Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote ...
CVE-2022-29164HIGH7.1Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. In affe...
CVE-2022-29161CRITICAL9.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypt...
CVE-2022-24903HIGH8.1Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overfl...
CVE-2022-24902MEDIUM4.3TkVideoplayer is a simple library to play video files in tkinter. Uncontrolled memory consumption in versions of TKVideo...
CVE-2022-24899MEDIUM6.1Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In v...
CVE-2022-24884HIGH7.5ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` doe...
CVE-2022-24817CRITICAL9.9Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, he...
CVE-2022-29535CRITICAL9.8Zoho ManageEngine OPManager through 125588 allows SQL Injection via a few default reports.
CVE-2022-29175Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: This candidate was withdrawn. Further inves...
CVE-2022-29173HIGH8.8go-tuf is a Go implementation of The Update Framework (TUF). go-tuf does not correctly implement the client workflow for...
CVE-2022-29172MEDIUM6.1Auth0 is an authentication broker that supports both social and enterprise identity providers, including Active Director...
CVE-2022-29167HIGH7.5Hawk is an HTTP authentication scheme providing mechanisms for making authenticated HTTP requests with partial cryptogra...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now