2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-23572MEDIUM6.5Tensorflow is an Open Source Machine Learning Framework. Under certain scenarios, TensorFlow can fail to specialize a ty...
CVE-2022-23571MEDIUM6.5Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, a TensorFlow process can ...
CVE-2022-23570MEDIUM6.5Tensorflow is an Open Source Machine Learning Framework. When decoding a tensor from protobuf, TensorFlow might do a nul...
CVE-2022-23566HIGH8.8Tensorflow is an Open Source Machine Learning Framework. TensorFlow is vulnerable to a heap OOB write in `Grappler`. The...
CVE-2022-23565MEDIUM6.5Tensorflow is an Open Source Machine Learning Framework. An attacker can trigger denial of service via assertion failure...
CVE-2022-23564MEDIUM6.5Tensorflow is an Open Source Machine Learning Framework. When decoding a resource handle tensor from protobuf, a TensorF...
CVE-2022-23563MEDIUM6.3Tensorflow is an Open Source Machine Learning Framework. In multiple places, TensorFlow uses `tempfile.mktemp` to create...
CVE-2022-23562HIGH8.8Tensorflow is an Open Source Machine Learning Framework. The implementation of `Range` suffers from integer overflows. T...
CVE-2022-23561HIGH8.8Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause a write o...
CVE-2022-23560HIGH8.8Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would allow limited r...
CVE-2022-23559HIGH8.8Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an intege...
CVE-2022-23558HIGH8.8Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would cause an intege...
CVE-2022-23557MEDIUM6.5Tensorflow is an Open Source Machine Learning Framework. An attacker can craft a TFLite model that would trigger a divis...
CVE-2022-23379CRITICAL9.8Emlog v6.0 was discovered to contain a SQL injection vulnerability via the $TagID parameter of getblogidsfromtagid().
CVE-2022-22987CRITICAL9.8The affected product has a hardcoded private key available inside the project folder, which may allow an attacker to ach...
CVE-2022-22939MEDIUM4.9VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text wit...
CVE-2022-22804MEDIUM5.4A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that...
CVE-2022-22727HIGH8.8A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, chan...
CVE-2022-22726MEDIUM6.5A CWE-20: Improper Input Validation vulnerability exists that could allow arbitrary files on the server to be read by au...
CVE-2022-22725HIGH8.8A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing ...
CVE-2022-22724HIGH7.5A CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause a denial of service on ports 80 (HTTP...
CVE-2022-22723HIGH8.8A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing ...
CVE-2022-22722HIGH7.5A CWE-798: Use of Hard-coded Credentials vulnerability exists that could result in information disclosure. If an attacke...
CVE-2022-22689HIGH8.8CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a vulnerability in the CSV expor...
CVE-2022-22150HIGH8.8A memory corruption vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.1.0.52543. ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now