2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-33983HIGH7DMA transactions which are targeted at input buffers used for the NvmExpressLegacy software SMI handler could cause SMRA...
CVE-2022-33909HIGH7DMA transactions which are targeted at input buffers used for the HddPassword software SMI handler could cause SMRAM cor...
CVE-2022-33908HIGH7DMA transactions which are targeted at input buffers used for the SdHostDriver software SMI handler could cause SMRAM co...
CVE-2022-33905HIGH7DMA transactions which are targeted at input buffers used for the AhciBusDxe software SMI handler could cause SMRAM corr...
CVE-2022-43030HIGH7.2Siyucms v6.1.7 was discovered to contain a remote code execution (RCE) vulnerability in the background. SIYUCMS is a con...
CVE-2022-40735HIGH7.5The Diffie-Hellman Key Agreement Protocol allows use of long exponents that arguably make certain calculations unnecessa...
CVE-2022-34325HIGH7.8DMA transactions which are targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler could c...
CVE-2022-43146HIGH7.2An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers t...
CVE-2022-3238HIGH7.8A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneou...
CVE-2022-27896HIGH7.5Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing tha...
CVE-2022-44387HIGH8.8EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information componen...
CVE-2022-43323HIGH8.8EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component u...
CVE-2022-34320HIGH7.5 IBM CICS TX 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens...
CVE-2022-34319HIGH7.5IBM CICS TX 11.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensi...
CVE-2022-24938HIGH7.5 A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immed...
CVE-2022-43693HIGH8.8Concrete CMS is vulnerable to CSRF due to the lack of "State" parameter for external Concrete authentication service for...
CVE-2022-0324HIGH7.5There is a vulnerability in DHCPv6 packet parsing code that could be explored by remote attacker to craft a packet that ...
CVE-2022-43288HIGH8.8Rukovoditel v3.2.1 was discovered to contain a SQL injection vulnerability via the order_by parameter at /rukovoditel/in...
CVE-2022-40127HIGH8.8A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arb...
CVE-2022-27949HIGH7.5A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for task...
CVE-2022-45184HIGH7.2The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the conf...
CVE-2022-45183HIGH8.8Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with ...
CVE-2022-45199HIGH7.5Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
CVE-2022-45198HIGH7.5Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
CVE-2022-31630HIGH7.1In PHP versions prior to 7.4.33, 8.0.25 and 8.1.12, when using imageloadfont() function in gd extension, it is possible ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now