2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-48637HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bnxt: prevent skb UAF after handing over to PTP wor...
CVE-2022-48636HIGH7.8In the Linux kernel, the following vulnerability has been resolved: s390/dasd: fix Oops in dasd_alias_get_start_dev due...
CVE-2022-48635MEDIUM6.2In the Linux kernel, the following vulnerability has been resolved: fsdax: Fix infinite loop in dax_iomap_rw() I got a...
CVE-2022-48634MEDIUM5.3In the Linux kernel, the following vulnerability has been resolved: drm/gma500: Fix BUG: sleeping function called from ...
CVE-2022-48633MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/gma500: Fix WARN_ON(lock->magic != lock) error ...
CVE-2022-48632HIGH7.8In the Linux kernel, the following vulnerability has been resolved: i2c: mlxbf: prevent stack overflow in mlxbf_i2c_smb...
CVE-2022-48631MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug in extents parsing when eh_entries ==...
CVE-2022-48685MEDIUM6.7An issue was discovered in Logpoint 7.1 before 7.1.2. The daily executed cron file clean_secbi_old_logs is writable by a...
CVE-2022-48684HIGH8.8An issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search template. The search templat...
CVE-2022-48611HIGH7.8A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker ma...
CVE-2022-40975MEDIUM5.4Missing Authorization vulnerability in Aazztech Post Slider.This issue affects Post Slider: from n/a through 1.6.7.
CVE-2022-48682MEDIUM6In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink.
CVE-2022-36029MEDIUM6.1Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerabil...
CVE-2022-36028MEDIUM6.1Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerabil...
CVE-2022-45852MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FormAssembly / Drew Busc...
CVE-2022-46897MEDIUM5.3An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The CapsuleIFWUSmm driver does not check the re...
CVE-2022-35503HIGH7.5Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary c...
CVE-2022-34562MEDIUM6.1A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML vi...
CVE-2022-34561MEDIUM4.3A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML vi...
CVE-2022-34560HIGH7.1A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML vi...
CVE-2022-40745MEDIUM5.5IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to weaker than expect...
CVE-2022-47151HIGH8.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS He...
CVE-2022-41698MEDIUM6.5Missing Authorization vulnerability in Layered If Menu.This issue affects If Menu: from n/a through 0.16.3.
CVE-2022-24810HIGH8.8net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with ...
CVE-2022-24809MEDIUM6.5net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now