2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1201 | MEDIUM | 6.5 | 0.4% | Apr 2, 2022 | NULL Pointer Dereference in mrb_vm_exec with super in GitHub repository mruby/mruby prior to 3.2. This vulnerability is ... |
| CVE-2022-27534 | CRITICAL | 9.8 | 3.0% | Apr 1, 2022 | Kaspersky Anti-Virus products for home and Kaspersky Endpoint Security with antivirus databases released before 12 March... |
| CVE-2022-27177 | CRITICAL | 9.8 | 2.1% | Apr 1, 2022 | A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for al... |
| CVE-2022-26419 | HIGH | 7.8 | 2.0% | Apr 1, 2022 | Omron CX-Position (versions 2.5.3 and prior) is vulnerable to multiple stack-based buffer overflow conditions while pars... |
| CVE-2022-26417 | HIGH | 7.8 | 1.4% | Apr 1, 2022 | Omron CX-Position (versions 2.5.3 and prior) is vulnerable to a use after free memory condition while processing a speci... |
| CVE-2022-26022 | HIGH | 7.8 | 1.4% | Apr 1, 2022 | Omron CX-Position (versions 2.5.3 and prior) is vulnerable to an out-of-bounds write while processing a specific project... |
| CVE-2022-25959 | HIGH | 7.8 | 1.4% | Apr 1, 2022 | Omron CX-Position (versions 2.5.3 and prior) is vulnerable to memory corruption while processing a specific project file... |
| CVE-2022-25160 | MEDIUM | 5.9 | 1.1% | Apr 1, 2022 | Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versi... |
| CVE-2022-25159 | HIGH | 8.1 | 2.1% | Apr 1, 2022 | Authentication Bypass by Capture-replay vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions... |
| CVE-2022-25158 | CRITICAL | 9.1 | 1.3% | Apr 1, 2022 | Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versi... |
| CVE-2022-25157 | CRITICAL | 9.1 | 2.3% | Apr 1, 2022 | Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U... |
| CVE-2022-25156 | HIGH | 8.1 | 1.2% | Apr 1, 2022 | Use of Weak Hash vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U(C) CPU all versions, Mitsubishi Electric M... |
| CVE-2022-25155 | HIGH | 8.1 | 2.1% | Apr 1, 2022 | Use of Password Hash Instead of Password for Authentication vulnerability in Mitsubishi Electric MELSEC iQ-F series FX5U... |
| CVE-2022-22965 | CRITICAL | 9.8 | 99.7% | Apr 1, 2022 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data b... |
| CVE-2022-22963 | CRITICAL | 9.8 | 99.9% | Apr 1, 2022 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is po... |
| CVE-2022-22950 | MEDIUM | 6.5 | 36.7% | Apr 1, 2022 | n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specia... |
| CVE-2022-22570 | CRITICAL | 10 | 1.0% | Apr 1, 2022 | A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and e... |
| CVE-2022-21830 | MEDIUM | 6.1 | 0.8% | Apr 1, 2022 | A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pastin... |
| CVE-2022-1159 | HIGH | 7.2 | 3.4% | Apr 1, 2022 | Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator... |
| CVE-2022-1098 | HIGH | 7.8 | 0.2% | Apr 1, 2022 | Delta Electronics DIAEnergie (all versions prior to 1.8.02.004) are vulnerable to a DLL hijacking condition. When combin... |
| CVE-2022-1068 | HIGH | 7.5 | 0.9% | Apr 1, 2022 | Modbus Tools Modbus Slave (versions 7.4.2 and prior) is vulnerable to a stack-based buffer overflow in the registration ... |
| CVE-2022-1018 | MEDIUM | 5.5 | 2.1% | Apr 1, 2022 | When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vuln... |
| CVE-2022-0922 | MEDIUM | 6.5 | 0.4% | Apr 1, 2022 | The software does not perform any authentication for critical system functionality. |
| CVE-2022-0741 | HIGH | 7.5 | 1.4% | Apr 1, 2022 | Improper input validation in all versions of GitLab CE/EE using sendmail to send emails allowed an attacker to steal env... |
| CVE-2022-0489 | MEDIUM | 5.7 | 1.5% | Apr 1, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DO... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now