2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22515 | HIGH | 8.1 | 1.1% | Apr 7, 2022 | A remote, authenticated attacker could utilize the control program of the CODESYS Control runtime system to use the vuln... |
| CVE-2022-22514 | HIGH | 7.1 | 0.9% | Apr 7, 2022 | An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can sub... |
| CVE-2022-22513 | MEDIUM | 6.5 | 1.0% | Apr 7, 2022 | An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODES... |
| CVE-2022-0935 | HIGH | 8.8 | 1.3% | Apr 7, 2022 | Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97. |
| CVE-2022-0677 | HIGH | 7.5 | 1.2% | Apr 7, 2022 | Improper Handling of Length Parameter Inconsistency vulnerability in the Update Server component of Bitdefender Endpoint... |
| CVE-2022-27022 | CRITICAL | 9.8 | 1.7% | Apr 7, 2022 | There is a stack overflow vulnerability in the SetSysTimeCfg() function in the httpd service of Tenda AC9 V15.03.2.21_cn... |
| CVE-2022-27016 | CRITICAL | 9.8 | 1.7% | Apr 7, 2022 | There is a stack overflow vulnerability in the SetStaticRouteCfg() function in the httpd service of Tenda AC9 15.03.2.21... |
| CVE-2022-26627 | HIGH | 8.8 | 1.4% | Apr 7, 2022 | Online Project Time Management System v1.0 was discovered to contain an arbitrary file write vulnerability which allows ... |
| CVE-2022-25339 | MEDIUM | 5.5 | 0.2% | Apr 7, 2022 | ownCloud owncloud/android 2.20 has Incorrect Access Control for local attackers. |
| CVE-2022-25338 | MEDIUM | 6.8 | 0.2% | Apr 7, 2022 | ownCloud owncloud/android before 2.20 has Incorrect Access Control for physically proximate attackers. |
| CVE-2022-23900 | CRITICAL | 9.8 | 3.6% | Apr 7, 2022 | A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an att... |
| CVE-2022-27819 | MEDIUM | 5.3 | 0.8% | Apr 7, 2022 | SWHKD 1.1.5 allows unsafe parsing via the -c option. An information leak might occur but there is a simple denial of ser... |
| CVE-2022-27818 | CRITICAL | 9.1 | 1.7% | Apr 7, 2022 | SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service. |
| CVE-2022-26613 | CRITICAL | 9.8 | 1.4% | Apr 6, 2022 | PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability via the category parameter in categorymenu.php. |
| CVE-2022-26607 | HIGH | 7.2 | 2.4% | Apr 6, 2022 | A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbit... |
| CVE-2022-26605 | HIGH | 8.8 | 1.0% | Apr 6, 2022 | eZiosuite v2.0.7 contains an authenticated arbitrary file upload via the Avatar upload functionality. |
| CVE-2022-26591 | HIGH | 7.5 | 1.1% | Apr 6, 2022 | FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a ... |
| CVE-2022-20782 | MEDIUM | 6.5 | 1.0% | Apr 6, 2022 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2022-20781 | MEDIUM | 5.4 | 0.6% | Apr 6, 2022 | A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) c... |
| CVE-2022-20774 | HIGH | 8.1 | 0.4% | Apr 6, 2022 | A vulnerability in the web-based management interface of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform F... |
| CVE-2022-20763 | HIGH | 8.8 | 0.9% | Apr 6, 2022 | A vulnerability in the login authorization components of Cisco Webex Meetings could allow an authenticated, remote attac... |
| CVE-2022-20762 | HIGH | 7.8 | 0.3% | Apr 6, 2022 | A vulnerability in the Common Execution Environment (CEE) ConfD CLI of Cisco Ultra Cloud Core - Subscriber Microservices... |
| CVE-2022-20756 | HIGH | 7.5 | 1.4% | Apr 6, 2022 | A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote att... |
| CVE-2022-20755 | HIGH | 7.2 | 3.2% | Apr 6, 2022 | Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresenc... |
| CVE-2022-20754 | HIGH | 7.2 | 3.2% | Apr 6, 2022 | Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresenc... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now