2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29166 | HIGH | 8.8 | 0.9% | May 5, 2022 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate... |
| CVE-2022-29176 | HIGH | 7.5 | 1.7% | May 5, 2022 | Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action,... |
| CVE-2022-27411 | CRITICAL | 9.8 | 2.4% | May 5, 2022 | TOTOLINK N600R v5.3c.5507_B20171031 was discovered to contain a command injection vulnerability via the QUERY_STRING par... |
| CVE-2022-27360 | CRITICAL | 9.8 | 2.0% | May 5, 2022 | SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment. |
| CVE-2022-27359 | MEDIUM | 5.5 | 1.0% | May 5, 2022 | Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a this.maildoc NULL pointer dereference. |
| CVE-2022-27337 | MEDIUM | 6.5 | 1.5% | May 5, 2022 | A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a... |
| CVE-2022-28584 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setWiFiWpsStart interface in TOTOlink A7100RU (v7.4cu... |
| CVE-2022-28583 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setWiFiWpsCfg interface in TOTOlink A7100RU (v7.4cu.2... |
| CVE-2022-28582 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setWiFiSignalCfg interface in TOTOlink A7100RU (v7.4c... |
| CVE-2022-28581 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setWiFiAdvancedCfg interface in TOTOlink A7100RU (v7.... |
| CVE-2022-28580 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setL2tpServerCfg interface in TOTOlink A7100RU (v7.4c... |
| CVE-2022-28579 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setParentalRules interface in TOTOlink A7100RU (v7.4c... |
| CVE-2022-28578 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setOpenVpnCfg interface in TOTOlink A7100RU (v7.4cu.2... |
| CVE-2022-28577 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the delParentalRules interface in TOTOlink A7100RU (v7.4c... |
| CVE-2022-28575 | CRITICAL | 9.8 | 2.9% | May 5, 2022 | It is found that there is a command injection vulnerability in the setopenvpnclientcfg interface in TOTOlink A7100RU (v7... |
| CVE-2022-26073 | MEDIUM | 6.5 | 0.7% | May 5, 2022 | A denial of service vulnerability exists in the libxm_av.so DemuxCmdInBuffer functionality of Anker Eufy Homebase 2 2.1.... |
| CVE-2022-25989 | HIGH | 8.8 | 1.0% | May 5, 2022 | An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1... |
| CVE-2022-29592 | CRITICAL | 9.8 | 19.3% | May 5, 2022 | Tenda TX9 Pro 22.03.02.10 devices allow OS command injection via set_route (called by doSystemCmd_route). |
| CVE-2022-29502 | CRITICAL | 9.8 | 1.6% | May 5, 2022 | SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges. |
| CVE-2022-29501 | HIGH | 8.8 | 2.5% | May 5, 2022 | SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execu... |
| CVE-2022-29500 | HIGH | 8.8 | 2.0% | May 5, 2022 | SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure. |
| CVE-2022-29491 | HIGH | 7.5 | 0.9% | May 5, 2022 | On F5 BIG-IP LTM, Advanced WAF, ASM, or APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x v... |
| CVE-2022-29480 | MEDIUM | 5.3 | 0.8% | May 5, 2022 | On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are con... |
| CVE-2022-29479 | MEDIUM | 5.3 | 0.8% | May 5, 2022 | On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and ... |
| CVE-2022-29474 | MEDIUM | 4.3 | 1.4% | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now