2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41444 | MEDIUM | 6.1 | 0.6% | Aug 22, 2023 | Cross Site Scripting (XSS) vulnerability in Cacti 1.2.21 via crafted POST request to graphs_new.php. |
| CVE-2022-40433 | — | — | — | Aug 22, 2023 | Rejected reason: ** REJECT ** This CVE ID has been rejected by its CNA as it was not a security issue. |
| CVE-2022-40090 | MEDIUM | 6.5 | 0.8% | Aug 22, 2023 | An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service... |
| CVE-2022-38349 | MEDIUM | 6.5 | 0.9% | Aug 22, 2023 | An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service b... |
| CVE-2022-37052 | MEDIUM | 6.5 | 0.9% | Aug 22, 2023 | A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failur... |
| CVE-2022-37051 | MEDIUM | 6.5 | 1.0% | Aug 22, 2023 | An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main... |
| CVE-2022-37050 | MEDIUM | 6.5 | 0.9% | Aug 22, 2023 | In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes w... |
| CVE-2022-36648 | CRITICAL | 10 | 1.4% | Aug 22, 2023 | The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allo... |
| CVE-2022-35206 | MEDIUM | 5.5 | 0.3% | Aug 22, 2023 | Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwar... |
| CVE-2022-35205 | MEDIUM | 5.5 | 0.4% | Aug 22, 2023 | An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows ... |
| CVE-2022-34038 | HIGH | 7.5 | 1.3% | Aug 22, 2023 | Etcd v3.5.4 allows remote attackers to cause a denial of service via function PageWriter.write in pagewriter.go. NOTE: t... |
| CVE-2022-29654 | MEDIUM | 5.5 | 0.5% | Aug 22, 2023 | Buffer overflow vulnerability in quote_for_pmake in asm/nasm.c in nasm before 2.15.05 allows attackers to cause a denial... |
| CVE-2022-28073 | HIGH | 7.5 | 0.7% | Aug 22, 2023 | A use after free in r_reg_set_value function in radare2 5.4.2 and 5.4.0. |
| CVE-2022-28072 | HIGH | 7.5 | 0.7% | Aug 22, 2023 | A heap buffer overflow in r_read_le32 function in radare25.4.2 and 5.4.0. |
| CVE-2022-28071 | HIGH | 7.5 | 0.7% | Aug 22, 2023 | A use after free in r_reg_get_name_idx function in radare2 5.4.2 and 5.4.0. |
| CVE-2022-28070 | HIGH | 7.5 | 0.7% | Aug 22, 2023 | A null pointer deference in __core_anal_fcn function in radare2 5.4.2 and 5.4.0. |
| CVE-2022-28069 | HIGH | 7.5 | 0.7% | Aug 22, 2023 | A heap buffer overflow in vax_opfunction in radare2 5.4.2 and 5.4.0. |
| CVE-2022-28068 | HIGH | 7.5 | 0.7% | Aug 22, 2023 | A heap buffer overflow in r_sleb128 function in radare2 5.4.2 and 5.4.0. |
| CVE-2022-26592 | HIGH | 8.8 | 0.8% | Aug 22, 2023 | Stack Overflow vulnerability in libsass 3.6.5 via the CompoundSelector::has_real_parent_ref function. |
| CVE-2022-25024 | HIGH | 7.5 | 1.0% | Aug 22, 2023 | The json2xml package through 3.12.0 for Python allows an error in typecode decoding enabling a remote attack that can le... |
| CVE-2022-4367 | — | — | — | Aug 21, 2023 | Rejected reason: Duplicate, use CVE-2023-4279 instead. |
| CVE-2022-46751 | HIGH | 8.2 | 1.8% | Aug 21, 2023 | Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache... |
| CVE-2022-24989 | CRITICAL | 9.8 | 31.9% | Aug 20, 2023 | TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via the raidtype and diskst... |
| CVE-2022-4894 | HIGH | 7.3 | 0.2% | Aug 16, 2023 | Certain HP and Samsung Printer software packages may potentially be vulnerable to elevation of privilege due to Uncontro... |
| CVE-2022-4782 | MEDIUM | 5.4 | 0.4% | Aug 16, 2023 | The ClickFunnels WordPress plugin through 3.1.1 does not validate and escape one of its shortcode attributes, which coul... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now