2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-23730CRITICAL9.8The public API error causes for the attacker to be able to bypass API access control.
CVE-2022-23625MEDIUM6.5Wire-ios is a messaging application using the wire protocol on apple's ios platform. In versions prior to 3.95 malformed...
CVE-2022-23187HIGH7.8Adobe Illustrator version 26.0.3 (and earlier) is affected by a buffer overflow vulnerability due to insecure handling o...
CVE-2022-0924MEDIUM5.5Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff fil...
CVE-2022-0921MEDIUM6.7Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2....
CVE-2022-0909MEDIUM5.5Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file....
CVE-2022-0908MEDIUM5.5Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff ...
CVE-2022-0907MEDIUM5.5Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-se...
CVE-2022-0853HIGH7.5A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using Use...
CVE-2022-0002MEDIUM6.5Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to...
CVE-2022-0001MEDIUM6.5Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authoriz...
CVE-2022-24433CRITICAL9.8The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(...
CVE-2022-0932MEDIUM6.5Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.
CVE-2022-21819HIGH7.6NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unpr...
CVE-2022-0860CRITICAL9.1Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
CVE-2022-0871CRITICAL9.1Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.
CVE-2022-0928MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0870MEDIUM5.3Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.
CVE-2022-0913HIGH7.5Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0912MEDIUM4.8Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11.
CVE-2022-23402CRITICAL9.8The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5...
CVE-2022-23401HIGH7.8The following Yokogawa Electric products contain insecure DLL loading issues. CENTUM CS 3000 versions from R3.08.10 to R...
CVE-2022-22729HIGH8.8CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets....
CVE-2022-22151HIGH8.1CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: ...
CVE-2022-22148HIGH7.8'Root Service' service implemented in the following Yokogawa Electric products creates some named pipe with improper ACL...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now