2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-43595MEDIUM5.9Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenIm...
CVE-2022-43594MEDIUM5.9Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenIm...
CVE-2022-43593MEDIUM5.9A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4...
CVE-2022-43592MEDIUM5.9An information disclosure vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageI...
CVE-2022-41684MEDIUM5.5A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file dir...
CVE-2022-36354MEDIUM5.3A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.1...
CVE-2022-22458MEDIUM6.5 IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read b...
CVE-2022-22457MEDIUM4.4IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain...
CVE-2022-22456MEDIUM6.1 IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allow...
CVE-2022-43859MEDIUM4.3IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object th...
CVE-2022-43858MEDIUM4.3IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files the...
CVE-2022-43857MEDIUM4.3IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are ...
CVE-2022-3794MEDIUM4.3The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up ...
CVE-2022-46880MEDIUM6.5A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: ...
CVE-2022-46877MEDIUM4.3By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user...
CVE-2022-46875MEDIUM6.5The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a use...
CVE-2022-45420MEDIUM6.5Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of t...
CVE-2022-45419MEDIUM6.5If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server th...
CVE-2022-45418MEDIUM6.1If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the brow...
CVE-2022-45417MEDIUM4.3Service Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers bei...
CVE-2022-45416MEDIUM6.5Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing...
CVE-2022-45413MEDIUM6.1Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause ...
CVE-2022-45411MEDIUM6.1Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access ...
CVE-2022-45410MEDIUM6.5When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the Se...
CVE-2022-45408MEDIUM6.5Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seein...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now