2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-30260HIGH7.8Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate check...
CVE-2022-26964HIGH7.5Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure vi...
CVE-2022-41318HIGH8.6A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection,...
CVE-2022-40005HIGH8.8Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the...
CVE-2022-37706HIGH7.8enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th...
CVE-2022-42898HIGH8.8PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to r...
CVE-2022-45893HIGH8.8Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user ...
CVE-2022-45197HIGH7.5Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server ...
CVE-2022-44017HIGH7.5An issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can l...
CVE-2022-44016HIGH7.5An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can download arbitrary files from the web ...
CVE-2022-42953HIGH7.5Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct r...
CVE-2022-45889HIGH7.2Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records ...
CVE-2022-46175HIGH8.8JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for con...
CVE-2022-45798HIGH7.8A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One a...
CVE-2022-38658HIGH7.5BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix ope...
CVE-2022-47633HIGH8.1An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a ma...
CVE-2022-28229HIGH7.5The hash functionality in userver before 42059b6319661583b3080cab9b595d4f8ac48128 allows attackers to cause a denial of ...
CVE-2022-23854HIGH7.5AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an ...
CVE-2022-41290HIGH8.4IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the rm_rlcache...
CVE-2022-46570HIGH7.2D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password ...
CVE-2022-46569HIGH7.2D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Key param...
CVE-2022-46568HIGH7.2D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the AccountPa...
CVE-2022-46566HIGH7.2D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password ...
CVE-2022-46563HIGH7.2D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password ...
CVE-2022-46562HIGH7.2D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the PSK param...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now