2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0156 | MEDIUM | 5.5 | 1.7% | Jan 10, 2022 | vim is vulnerable to Use After Free |
| CVE-2022-22847 | CRITICAL | 9.8 | 1.2% | Jan 10, 2022 | Formpipe Lasernet before 9.13.3 allows file inclusion in Client Web Services (either by an authenticated attacker, or in... |
| CVE-2022-22846 | MEDIUM | 5.3 | 0.8% | Jan 10, 2022 | The dnslib package through 0.9.16 for Python does not verify that the ID value in a DNS reply matches an ID value in a q... |
| CVE-2022-22845 | CRITICAL | 9.8 | 3.8% | Jan 10, 2022 | QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key a... |
| CVE-2022-22844 | MEDIUM | 5.5 | 1.3% | Jan 10, 2022 | LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x... |
| CVE-2022-22836 | MEDIUM | 6.5 | 5.4% | Jan 10, 2022 | CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP... |
| CVE-2022-22827 | HIGH | 8.8 | 2.8% | Jan 10, 2022 | storeAtts in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
| CVE-2022-22826 | HIGH | 8.8 | 2.8% | Jan 10, 2022 | nextScaffoldPart in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
| CVE-2022-22825 | HIGH | 8.8 | 2.6% | Jan 10, 2022 | lookup in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
| CVE-2022-22824 | CRITICAL | 9.8 | 3.4% | Jan 10, 2022 | defineAttribute in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
| CVE-2022-22823 | CRITICAL | 9.8 | 3.4% | Jan 10, 2022 | build_model in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
| CVE-2022-22822 | CRITICAL | 9.8 | 4.8% | Jan 10, 2022 | addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow. |
| CVE-2022-22821 | MEDIUM | 4.4 | 0.3% | Jan 10, 2022 | NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any... |
| CVE-2022-22817 | CRITICAL | 9.8 | 3.4% | Jan 10, 2022 | PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python e... |
| CVE-2022-22816 | MEDIUM | 6.5 | 2.0% | Jan 10, 2022 | path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path. |
| CVE-2022-22815 | MEDIUM | 6.5 | 2.6% | Jan 10, 2022 | path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path. |
| CVE-2022-22702 | MEDIUM | 4.3 | 0.7% | Jan 10, 2022 | PartKeepr versions up to v1.4.0, in the functionality to upload attachments using a URL when creating a part does not va... |
| CVE-2022-22701 | MEDIUM | 6.5 | 1.0% | Jan 10, 2022 | PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://'... |
| CVE-2022-22289 | MEDIUM | 5.3 | 0.8% | Jan 10, 2022 | Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive infor... |
| CVE-2022-22288 | HIGH | 7.5 | 0.9% | Jan 10, 2022 | Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist. |
| CVE-2022-22287 | MEDIUM | 4.6 | 0.2% | Jan 10, 2022 | Abitrary file access vulnerability in Samsung Email prior to 6.1.60.16 allows attacker to read isolated data in sandbox. |
| CVE-2022-22286 | HIGH | 7.1 | 0.3% | Jan 10, 2022 | A vulnerability using PendingIntent in Bixby Routines prior to version 3.1.21.8 in Android R(11.0) and 2.6.30.5 in Andro... |
| CVE-2022-22285 | HIGH | 7.1 | 0.3% | Jan 10, 2022 | A vulnerability using PendingIntent in Reminder prior to version 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Androi... |
| CVE-2022-22284 | MEDIUM | 5.5 | 0.2% | Jan 10, 2022 | Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode pass... |
| CVE-2022-22283 | LOW | 3.3 | 0.2% | Jan 10, 2022 | Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now