2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-48626HIGH7.8In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after-free on remove path...
CVE-2022-34357MEDIUM6.5IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or a...
CVE-2022-43842CRITICAL9.1IBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ...
CVE-2022-25377HIGH7.5The ACME-challenge endpoint in Appwrite 0.5.0 through 0.12.x before 0.12.2 allows remote attackers to read arbitrary loc...
CVE-2022-45179MEDIUM5.4An issue was discovered in LIVEBOX Collaboration vDesk through v031. A basic XSS vulnerability exists under the /api/v1/...
CVE-2022-45177HIGH7.5An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under ...
CVE-2022-45169MEDIUM5.4An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redire...
CVE-2022-45320MEDIUM6.3Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 all...
CVE-2022-48625HIGH7.5Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an...
CVE-2022-48624HIGH7.8close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
CVE-2022-48621HIGH7.5Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulne...
CVE-2022-42443CRITICAL9.8An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions p...
CVE-2022-41738HIGH7.5IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connectio...
CVE-2022-41737MEDIUM6.5IBM Storage Scale Container Native Storage Access 5.1.2.1 through 5.1.7.0 could allow a local attacker to initiate conne...
CVE-2022-23093MEDIUM6.5ping reads raw IP packets from the network to process responses in the pr_pack() function. As part of processing a resp...
CVE-2022-23092HIGH8.8The implementation of lib9p's handling of RWALK messages was missing a bounds check needed when unpacking the message co...
CVE-2022-23091MEDIUM4A particular case of memory sharing is mishandled in the virtual memory system. This is very similar to SA-21:08.vm, bu...
CVE-2022-23090HIGH7.7The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error ca...
CVE-2022-23089MEDIUM4.7When dumping core and saving process information, proc_getargv() might return an sbuf which have a sbuf_len() of 0 or -1...
CVE-2022-23088CRITICAL9.8The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-...
CVE-2022-23087HIGH8.8The e1000 network adapters permit a variety of modifications to an Ethernet packet when it is being transmitted. These ...
CVE-2022-23086HIGH7.8Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified si...
CVE-2022-23085HIGH8.2A user-provided integer option was passed to nmreq_copyin() without checking if it would overflow. This insufficient bo...
CVE-2022-23084HIGH7.5The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This...
CVE-2022-48220MEDIUM6.4Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now