2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1201MEDIUM6.5NULL Pointer Dereference in mrb_vm_exec with super in GitHub repository mruby/mruby prior to 3.2. This vulnerability is ...
CVE-2022-27534CRITICAL9.8Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March...
CVE-2022-27177CRITICAL9.8A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for al...
CVE-2022-26419HIGH7.8Omron CX-Position (versions 2.5.3 and prior) is vulnerable to multiple stack-based buffer overflow conditions while pars...
CVE-2022-26417HIGH7.8Omron CX-Position (versions 2.5.3 and prior) is vulnerable to a use after free memory condition while processing a speci...
CVE-2022-26022HIGH7.8Omron CX-Position (versions 2.5.3 and prior) is vulnerable to an out-of-bounds write while processing a specific project...
CVE-2022-25959HIGH7.8Omron CX-Position (versions 2.5.3 and prior) is vulnerable to memory corruption while processing a specific project file...
CVE-2022-25160MEDIUM5.9Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versi...
CVE-2022-25159HIGH8.1Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions...
CVE-2022-25158CRITICAL9.1Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versi...
CVE-2022-25157CRITICAL9.1Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U...
CVE-2022-25156HIGH8.1Use of Weak Hash vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric M...
CVE-2022-25155HIGH8.1Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U...
CVE-2022-22965CRITICAL9.8A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b...
CVE-2022-22963CRITICAL9.8In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po...
CVE-2022-22950MEDIUM6.5n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specia...
CVE-2022-22570CRITICAL10A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and e...
CVE-2022-21830MEDIUM6.1A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pastin...
CVE-2022-1159HIGH7.2Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator...
CVE-2022-1098HIGH7.8Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combin...
CVE-2022-1068HIGH7.5Modbus Tools Modbus Slave (versions 7.4.2 and prior) is vulnerable to a stack-based buffer overflow in the registration ...
CVE-2022-1018MEDIUM5.5When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vuln...
CVE-2022-0922MEDIUM6.5The software does not perform any authentication for critical system functionality.
CVE-2022-0741HIGH7.5Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal env...
CVE-2022-0489MEDIUM5.7An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DO...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now