2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0156MEDIUM5.5vim is vulnerable to Use After Free
CVE-2022-22847CRITICAL9.8Formpipe Lasernet before 9.13.3 allows file inclusion in Client Web Services (either by an authenticated attacker, or in...
CVE-2022-22846MEDIUM5.3The dnslib package through 0.9.16 for Python does not verify that the ID value in a DNS reply matches an ID value in a q...
CVE-2022-22845CRITICAL9.8QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key a...
CVE-2022-22844MEDIUM5.5LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x...
CVE-2022-22836MEDIUM6.5CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP...
CVE-2022-22827HIGH8.8storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CVE-2022-22826HIGH8.8nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CVE-2022-22825HIGH8.8lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CVE-2022-22824CRITICAL9.8defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CVE-2022-22823CRITICAL9.8build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CVE-2022-22822CRITICAL9.8addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.
CVE-2022-22821MEDIUM4.4NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any...
CVE-2022-22817CRITICAL9.8PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python e...
CVE-2022-22816MEDIUM6.5path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.
CVE-2022-22815MEDIUM6.5path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
CVE-2022-22702MEDIUM4.3PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not va...
CVE-2022-22701MEDIUM6.5PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://'...
CVE-2022-22289MEDIUM5.3Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive infor...
CVE-2022-22288HIGH7.5Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.
CVE-2022-22287MEDIUM4.6Abitrary file access vulnerability in Samsung Email prior to 6.1.60.16 allows attacker to read isolated data in sandbox.
CVE-2022-22286HIGH7.1A vulnerability using PendingIntent in Bixby Routines prior to version 3.1.21.8 in Android R(11.0) and 2.6.30.5 in Andro...
CVE-2022-22285HIGH7.1A vulnerability using PendingIntent in Reminder prior to version 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Androi...
CVE-2022-22284MEDIUM5.5Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode pass...
CVE-2022-22283LOW3.3Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now