2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-20051MEDIUM5.5In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could le...
CVE-2022-20050MEDIUM6.7In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local ...
CVE-2022-20049MEDIUM6.7In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalati...
CVE-2022-20048HIGH7.8In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escala...
CVE-2022-20047HIGH7.8In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local escala...
CVE-2022-0904MEDIUM6.5A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an atta...
CVE-2022-0903HIGH7.5A call stack overflow bug in the SAML login feature in Mattermost server in versions up to and including 6.3.2 allows an...
CVE-2022-0891HIGH7.1A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to...
CVE-2022-0865MEDIUM6.5Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. Fo...
CVE-2022-0856MEDIUM6.5libcaca is affected by a Divide By Zero issue via img2txt, which allows a remote malicious user to cause a Denial of Ser...
CVE-2022-0847HIGH7.8A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop...
CVE-2022-0813HIGH7.5PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid request...
CVE-2022-0725HIGH7.5A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to...
CVE-2022-0618HIGH7.5A program using swift-nio-http2 is vulnerable to a denial of service attack, caused by a network peer sending a speciall...
CVE-2022-0516HIGH7.8A vulnerability was found in kvm_s390_guest_sida_op in the arch/s390/kvm/kvm-s390.c function in KVM for s390 in the Linu...
CVE-2022-0507HIGH8.8Found a potential security vulnerability inside the Pandora API. Affected Pandora FMS version range: all versions of NG ...
CVE-2022-0433MEDIUM5.5A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_nex...
CVE-2022-0204HIGH8.8A heap overflow vulnerability was found in bluez in versions prior to 5.63. An attacker with local network access could ...
CVE-2022-0906MEDIUM4.8Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12.
CVE-2022-0905HIGH7.1Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.
CVE-2022-0895CRITICAL9.8Static Code Injection in GitHub repository microweber/microweber prior to 1.3.
CVE-2022-0890MEDIUM5.5NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2.
CVE-2022-24753HIGH7Stripe CLI is a command-line tool for the Stripe eCommerce platform. A vulnerability in Stripe CLI exists on Windows whe...
CVE-2022-24748HIGH7.5Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In versions p...
CVE-2022-24747MEDIUM5.3Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected vers...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now