2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24769 | MEDIUM | 5.9 | 0.5% | Mar 24, 2022 | Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in ... |
| CVE-2022-22374 | CRITICAL | 9.1 | 1.0% | Mar 24, 2022 | The BMC (IBM Power 9 AC922 OP910, OP920, OP930, and OP940) may be subject to a firmware downgrade attack which may affec... |
| CVE-2022-25568 | HIGH | 7.5 | 6.8% | Mar 24, 2022 | MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To explo... |
| CVE-2022-21820 | MEDIUM | 6.3 | 17.0% | Mar 24, 2022 | NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions witho... |
| CVE-2022-0153 | HIGH | 7.5 | 1.1% | Mar 24, 2022 | SQL Injection in GitHub repository forkcms/forkcms prior to 5.11.1. |
| CVE-2022-26629 | CRITICAL | 9.1 | 3.2% | Mar 24, 2022 | An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due... |
| CVE-2022-1058 | MEDIUM | 6.1 | 53.2% | Mar 24, 2022 | Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5. |
| CVE-2022-0955 | MEDIUM | 4.8 | 0.6% | Mar 24, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/data-hub prior to 1.2.4. |
| CVE-2022-0551 | HIGH | 7.2 | 0.9% | Mar 24, 2022 | Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticat... |
| CVE-2022-0550 | HIGH | 7.2 | 0.9% | Mar 24, 2022 | Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an auth... |
| CVE-2022-1052 | MEDIUM | 5.5 | 0.4% | Mar 24, 2022 | Heap Buffer Overflow in iterate_chained_fixups in GitHub repository radareorg/radare2 prior to 5.6.6. |
| CVE-2022-0145 | MEDIUM | 5.4 | 0.7% | Mar 24, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository forkcms/forkcms prior to 5.11.1. |
| CVE-2022-1061 | HIGH | 7.5 | 0.9% | Mar 24, 2022 | Heap Buffer Overflow in parseDragons in GitHub repository radareorg/radare2 prior to 5.6.8. |
| CVE-2022-0315 | HIGH | 7.5 | 0.9% | Mar 24, 2022 | Insecure Temporary File in GitHub repository horovod/horovod prior to 0.24.0. |
| CVE-2022-27820 | MEDIUM | 4 | 0.7% | Mar 24, 2022 | OWASP Zed Attack Proxy (ZAP) through w2022-03-21 does not verify the TLS certificate chain of an HTTPS server. |
| CVE-2022-27811 | CRITICAL | 9.8 | 3.0% | Mar 24, 2022 | GNOME OCRFeeder before 0.8.4 allows OS command injection via shell metacharacters in a PDF or image filename. |
| CVE-2022-27083 | CRITICAL | 9.8 | 2.9% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/upl... |
| CVE-2022-27082 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetI... |
| CVE-2022-27081 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetL... |
| CVE-2022-27080 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setW... |
| CVE-2022-27079 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setP... |
| CVE-2022-27078 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setA... |
| CVE-2022-27077 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/upl... |
| CVE-2022-27076 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/delA... |
| CVE-2022-26536 | CRITICAL | 9.8 | 2.7% | Mar 24, 2022 | Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setF... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now