2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43595 | MEDIUM | 5.9 | 1.2% | Dec 22, 2022 | Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenIm... |
| CVE-2022-43594 | MEDIUM | 5.9 | 1.3% | Dec 22, 2022 | Multiple denial of service vulnerabilities exist in the image output closing functionality of OpenImageIO Project OpenIm... |
| CVE-2022-43593 | MEDIUM | 5.9 | 1.3% | Dec 22, 2022 | A denial of service vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageIO v2.4... |
| CVE-2022-43592 | MEDIUM | 5.9 | 1.1% | Dec 22, 2022 | An information disclosure vulnerability exists in the DPXOutput::close() functionality of OpenImageIO Project OpenImageI... |
| CVE-2022-41684 | MEDIUM | 5.5 | 0.8% | Dec 22, 2022 | A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file dir... |
| CVE-2022-36354 | MEDIUM | 5.3 | 0.8% | Dec 22, 2022 | A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.1... |
| CVE-2022-22458 | MEDIUM | 6.5 | 0.8% | Dec 22, 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read b... |
| CVE-2022-22457 | MEDIUM | 4.4 | 0.1% | Dec 22, 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain... |
| CVE-2022-22456 | MEDIUM | 6.1 | 0.3% | Dec 22, 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allow... |
| CVE-2022-43859 | MEDIUM | 4.3 | 0.6% | Dec 22, 2022 | IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object th... |
| CVE-2022-43858 | MEDIUM | 4.3 | 1.0% | Dec 22, 2022 | IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files the... |
| CVE-2022-43857 | MEDIUM | 4.3 | 1.0% | Dec 22, 2022 | IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are ... |
| CVE-2022-3794 | MEDIUM | 4.3 | 0.6% | Dec 22, 2022 | The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up ... |
| CVE-2022-46880 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: ... |
| CVE-2022-46877 | MEDIUM | 4.3 | 0.7% | Dec 22, 2022 | By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user... |
| CVE-2022-46875 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a use... |
| CVE-2022-45420 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of t... |
| CVE-2022-45419 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | If the user added a security exception for an invalid TLS certificate, opened an ongoing TLS connection with a server th... |
| CVE-2022-45418 | MEDIUM | 6.1 | 0.7% | Dec 22, 2022 | If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the brow... |
| CVE-2022-45417 | MEDIUM | 4.3 | 0.4% | Dec 22, 2022 | Service Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers bei... |
| CVE-2022-45416 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing... |
| CVE-2022-45413 | MEDIUM | 6.1 | 0.4% | Dec 22, 2022 | Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause ... |
| CVE-2022-45411 | MEDIUM | 6.1 | 0.6% | Dec 22, 2022 | Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access ... |
| CVE-2022-45410 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the Se... |
| CVE-2022-45408 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seein... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now