2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-46869HIGH7.8Local privilege escalation during installation due to improper soft link handling. The following products are affected: ...
CVE-2022-40214Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requ...
CVE-2022-46868HIGH7.8Local privilege escalation during recovery due to improper soft link handling. The following products are affected: Acro...
CVE-2022-45451HIGH7.8Local privilege escalation due to insecure driver communication port permissions. The following products are affected: A...
CVE-2022-1601MEDIUM5.3The User Access Manager WordPress plugin before 2.2.18 prioritizes getting a visitor's IP from certain HTTP headers over...
CVE-2022-46783MEDIUM5.3An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may ...
CVE-2022-43904HIGH7.5IBM Security Guardium 11.3 and 11.4 could disclose sensitive information to an attacker due to improper restriction of e...
CVE-2022-43909MEDIUM5.4IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2022-43907HIGH8.8IBM Security Guardium 11.4 could allow a remote authenticated attacker to execute arbitrary commands on the system by se...
CVE-2022-4452HIGH8.8Insufficient data validation in crosvm in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially ...
CVE-2022-46884HIGH8.8A potential use-after-free vulnerability existed in SVG Images if the Refresh Driver was destroyed at an inopportune tim...
CVE-2022-3746MEDIUM6.7A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local ...
CVE-2022-3745MEDIUM4.4A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local ...
CVE-2022-3744MEDIUM6.7A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local ...
CVE-2022-3743MEDIUM4.4A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local ...
CVE-2022-3742MEDIUM6.7A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local ...
CVE-2022-48571HIGH7.5memcached 1.6.7 allows a Denial of Service via multi-packet uploads in UDP.
CVE-2022-48570HIGH7.5Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation. Function FixedSizeAllocatorWithCleanu...
CVE-2022-48566MEDIUM5.9An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations ...
CVE-2022-48565CRITICAL9.8An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity ...
CVE-2022-48564MEDIUM6.5read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when...
CVE-2022-48560HIGH7.5A use-after-free exists in Python through 3.9 via heappushpop in heapq.
CVE-2022-48554MEDIUM5.5File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Sou...
CVE-2022-48547MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Cacti 0.8.7g and earlier allows unauthenticated remote attackers...
CVE-2022-48545MEDIUM5.5An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now