2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26255 | CRITICAL | 9.8 | 1.7% | Mar 28, 2022 | Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxi... |
| CVE-2022-26254 | MEDIUM | 5.3 | 0.8% | Mar 27, 2022 | WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows ... |
| CVE-2022-26252 | MEDIUM | 6.5 | 1.8% | Mar 27, 2022 | aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain th... |
| CVE-2022-26245 | CRITICAL | 9.8 | 14.8% | Mar 27, 2022 | Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/ho... |
| CVE-2022-1106 | CRITICAL | 9.1 | 1.0% | Mar 27, 2022 | use after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2. |
| CVE-2022-27948 | MEDIUM | 4.3 | 1.4% | Mar 27, 2022 | Certain Tesla vehicles through 2022-03-26 allow attackers to open the charging port via a 315 MHz RF signal containing a... |
| CVE-2022-26205 | CRITICAL | 9.8 | 1.9% | Mar 27, 2022 | Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display tex... |
| CVE-2022-26620 | — | — | — | Mar 27, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-26200 | — | — | — | Mar 27, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-26198 | CRITICAL | 9.8 | 1.6% | Mar 27, 2022 | Notable v1.8.4 does not filter text editing, allowing attackers to execute arbitrary code via a crafted payload injected... |
| CVE-2022-27947 | HIGH | 8.8 | 2.8% | Mar 26, 2022 | NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via she... |
| CVE-2022-27946 | HIGH | 8.8 | 3.2% | Mar 26, 2022 | NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via she... |
| CVE-2022-27945 | HIGH | 8.8 | 2.9% | Mar 26, 2022 | NETGEAR R8500 1.0.2.158 devices allow remote authenticated users to execute arbitrary commands (such as telnetd) via she... |
| CVE-2022-27943 | MEDIUM | 5.5 | 0.9% | Mar 26, 2022 | libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new. |
| CVE-2022-27942 | HIGH | 7.8 | 1.1% | Mar 26, 2022 | tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c. |
| CVE-2022-27941 | HIGH | 7.8 | 1.1% | Mar 26, 2022 | tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c. |
| CVE-2022-27940 | HIGH | 7.8 | 1.1% | Mar 26, 2022 | tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c. |
| CVE-2022-27939 | MEDIUM | 5.5 | 1.0% | Mar 26, 2022 | tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c. |
| CVE-2022-27938 | MEDIUM | 5.5 | 0.6% | Mar 26, 2022 | stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__... |
| CVE-2022-1071 | HIGH | 8.2 | 0.9% | Mar 26, 2022 | User after free in mrb_vm_exec in GitHub repository mruby/mruby prior to 3.2. |
| CVE-2022-22995 | CRITICAL | 9.8 | 2.7% | Mar 25, 2022 | The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of file... |
| CVE-2022-22274 | CRITICAL | 9.8 | 57.3% | Mar 25, 2022 | A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to ... |
| CVE-2022-24784 | LOW | 3.7 | 1.0% | Mar 25, 2022 | Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single characte... |
| CVE-2022-24783 | CRITICAL | 10 | 1.1% | Mar 25, 2022 | Deno is a runtime for JavaScript and TypeScript. The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are ... |
| CVE-2022-26659 | HIGH | 7.1 | 0.4% | Mar 25, 2022 | Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now