2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0382MEDIUM5.5An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol subsystem, in the way...
CVE-2022-0185HIGH8.4A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functio...
CVE-2022-24289HIGH8.8Hessian serialization is a network protocol that supports object-based transmission. Apache Cayenne's optional Remote Ob...
CVE-2022-24112CRITICAL9.8An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default co...
CVE-2022-0560MEDIUM6.1Open Redirect in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0557HIGH7.2OS Command Injection in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-24961CRITICAL9.8In Portainer Agent before 2.11.1, an API server can continue running even if not associated with a Portainer instance in...
CVE-2022-24959MEDIUM5.5An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevprivate in drivers/net/h...
CVE-2022-24958HIGH7.8drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.
CVE-2022-24955CRITICAL9.8Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files...
CVE-2022-24954CRITICAL9.8Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for...
CVE-2022-23806CRITICAL9.1Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situatio...
CVE-2022-23773HIGH7.5cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tag...
CVE-2022-23772HIGH7.5Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Me...
CVE-2022-24647HIGH8.1Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function.
CVE-2022-24646HIGH7.5Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-m...
CVE-2022-0554HIGH7.8Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
CVE-2022-24916HIGH7.5Optimism before @eth-optimism/l2geth@0.5.11 allows economic griefing because a balance is duplicated upon contract self-...
CVE-2022-23630HIGH7.5Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, Gradl...
CVE-2022-24568CRITICAL9.8Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input.
CVE-2022-23321MEDIUM4.8A persistent cross-site scripting (XSS) vulnerability exists on two input fields within the administrative panel when ed...
CVE-2022-20749CRITICAL9.8Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker t...
CVE-2022-20738CRITICAL9.8A vulnerability in the Cisco Umbrella Secure Web Gateway service could allow an unauthenticated, remote attacker to bypa...
CVE-2022-20712CRITICAL9.8Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker t...
CVE-2022-20711CRITICAL9.8Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker t...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now