2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23730 | CRITICAL | 9.8 | 1.0% | Mar 11, 2022 | The public API error causes for the attacker to be able to bypass API access control. |
| CVE-2022-23625 | MEDIUM | 6.5 | 1.2% | Mar 11, 2022 | Wire-ios is a messaging application using the wire protocol on apple's ios platform. In versions prior to 3.95 malformed... |
| CVE-2022-23187 | HIGH | 7.8 | 4.3% | Mar 11, 2022 | Adobe Illustrator version 26.0.3 (and earlier) is affected by a buffer overflow vulnerability due to insecure handling o... |
| CVE-2022-0924 | MEDIUM | 5.5 | 1.3% | Mar 11, 2022 | Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff fil... |
| CVE-2022-0921 | MEDIUM | 6.7 | 2.1% | Mar 11, 2022 | Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.... |
| CVE-2022-0909 | MEDIUM | 5.5 | 1.3% | Mar 11, 2022 | Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file.... |
| CVE-2022-0908 | MEDIUM | 5.5 | 1.3% | Mar 11, 2022 | Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff ... |
| CVE-2022-0907 | MEDIUM | 5.5 | 1.3% | Mar 11, 2022 | Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-se... |
| CVE-2022-0853 | HIGH | 7.5 | 1.4% | Mar 11, 2022 | A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using Use... |
| CVE-2022-0002 | MEDIUM | 6.5 | 0.5% | Mar 11, 2022 | Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to... |
| CVE-2022-0001 | MEDIUM | 6.5 | 0.5% | Mar 11, 2022 | Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authoriz... |
| CVE-2022-24433 | CRITICAL | 9.8 | 3.5% | Mar 11, 2022 | The package simple-git before 3.3.0 are vulnerable to Command Injection via argument injection. When calling the .fetch(... |
| CVE-2022-0932 | MEDIUM | 6.5 | 1.0% | Mar 11, 2022 | Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2. |
| CVE-2022-21819 | HIGH | 7.6 | 0.4% | Mar 11, 2022 | NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unpr... |
| CVE-2022-0860 | CRITICAL | 9.1 | 2.3% | Mar 11, 2022 | Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2. |
| CVE-2022-0871 | CRITICAL | 9.1 | 1.4% | Mar 11, 2022 | Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5. |
| CVE-2022-0928 | MEDIUM | 5.4 | 2.4% | Mar 11, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12. |
| CVE-2022-0870 | MEDIUM | 5.3 | 3.4% | Mar 11, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5. |
| CVE-2022-0913 | HIGH | 7.5 | 1.4% | Mar 11, 2022 | Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3. |
| CVE-2022-0912 | MEDIUM | 4.8 | 0.5% | Mar 11, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11. |
| CVE-2022-23402 | CRITICAL | 9.8 | 1.0% | Mar 11, 2022 | The following Yokogawa Electric products hard-code the password for CAMS server applications: CENTUM VP versions from R5... |
| CVE-2022-23401 | HIGH | 7.8 | 0.2% | Mar 11, 2022 | The following Yokogawa Electric products contain insecure DLL loading issues. CENTUM CS 3000 versions from R3.08.10 to R... |
| CVE-2022-22729 | HIGH | 8.8 | 0.9% | Mar 11, 2022 | CAMS for HIS Server contained in the following Yokogawa Electric products improperly authenticate the receiving packets.... |
| CVE-2022-22151 | HIGH | 8.1 | 0.8% | Mar 11, 2022 | CAMS for HIS Log Server contained in the following Yokogawa Electric products fails to properly neutralize log outputs: ... |
| CVE-2022-22148 | HIGH | 7.8 | 0.2% | Mar 11, 2022 | 'Root Service' service implemented in the following Yokogawa Electric products creates some named pipe with improper ACL... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now