2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-33983 | HIGH | 7 | 0.2% | Nov 15, 2022 | DMA transactions which are targeted at input buffers used for the NvmExpressLegacy software SMI handler could cause SMRA... |
| CVE-2022-33909 | HIGH | 7 | 0.1% | Nov 15, 2022 | DMA transactions which are targeted at input buffers used for the HddPassword software SMI handler could cause SMRAM cor... |
| CVE-2022-33908 | HIGH | 7 | 0.1% | Nov 15, 2022 | DMA transactions which are targeted at input buffers used for the SdHostDriver software SMI handler could cause SMRAM co... |
| CVE-2022-33905 | HIGH | 7 | 0.1% | Nov 15, 2022 | DMA transactions which are targeted at input buffers used for the AhciBusDxe software SMI handler could cause SMRAM corr... |
| CVE-2022-43030 | HIGH | 7.2 | 1.9% | Nov 14, 2022 | Siyucms v6.1.7 was discovered to contain a remote code execution (RCE) vulnerability in the background. SIYUCMS is a con... |
| CVE-2022-40735 | HIGH | 7.5 | 2.3% | Nov 14, 2022 | The Diffie-Hellman Key Agreement Protocol allows use of long exponents that arguably make certain calculations unnecessa... |
| CVE-2022-34325 | HIGH | 7.8 | 0.1% | Nov 14, 2022 | DMA transactions which are targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler could c... |
| CVE-2022-43146 | HIGH | 7.2 | 1.0% | Nov 14, 2022 | An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers t... |
| CVE-2022-3238 | HIGH | 7.8 | 0.2% | Nov 14, 2022 | A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneou... |
| CVE-2022-27896 | HIGH | 7.5 | 0.4% | Nov 14, 2022 | Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing tha... |
| CVE-2022-44387 | HIGH | 8.8 | 0.3% | Nov 14, 2022 | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information componen... |
| CVE-2022-43323 | HIGH | 8.8 | 0.4% | Nov 14, 2022 | EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component u... |
| CVE-2022-34320 | HIGH | 7.5 | 0.5% | Nov 14, 2022 | IBM CICS TX 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens... |
| CVE-2022-34319 | HIGH | 7.5 | 0.5% | Nov 14, 2022 | IBM CICS TX 11.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensi... |
| CVE-2022-24938 | HIGH | 7.5 | 0.7% | Nov 14, 2022 | A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immed... |
| CVE-2022-43693 | HIGH | 8.8 | 0.4% | Nov 14, 2022 | Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for... |
| CVE-2022-0324 | HIGH | 7.5 | 1.1% | Nov 14, 2022 | There is a vulnerability in DHCPv6 packet parsing code that could be explored by remote attacker to craft a packet that ... |
| CVE-2022-43288 | HIGH | 8.8 | 0.8% | Nov 14, 2022 | Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the order_by parameter at /rukovoditel/in... |
| CVE-2022-40127 | HIGH | 8.8 | 85.7% | Nov 14, 2022 | A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arb... |
| CVE-2022-27949 | HIGH | 7.5 | 1.7% | Nov 14, 2022 | A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for task... |
| CVE-2022-45184 | HIGH | 7.2 | 1.9% | Nov 14, 2022 | The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the conf... |
| CVE-2022-45183 | HIGH | 8.8 | 0.8% | Nov 14, 2022 | Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with ... |
| CVE-2022-45199 | HIGH | 7.5 | 1.1% | Nov 14, 2022 | Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL. |
| CVE-2022-45198 | HIGH | 7.5 | 1.2% | Nov 14, 2022 | Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification). |
| CVE-2022-31630 | HIGH | 7.1 | 2.2% | Nov 14, 2022 | In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now