2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-41793HIGH7.8An out-of-bounds write vulnerability exists in the CSR format title functionality of Open Babel 3.1.1 and master commit ...
CVE-2022-37331HIGH7.8An out-of-bounds write vulnerability exists in the Gaussian format orientation functionality of Open Babel 3.1.1 and mas...
CVE-2022-2127MEDIUM5.9An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. Wh...
CVE-2022-28737HIGH7.8There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_im...
CVE-2022-28736HIGH7.8There's a use-after-free vulnerability in grub_cmd_chainloader() function; The chainloader command is used to boot up op...
CVE-2022-28735HIGH7.8The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such f...
CVE-2022-28734HIGH7Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally mov...
CVE-2022-28733HIGH8.1Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_n...
CVE-2022-40896MEDIUM5.5A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
CVE-2022-43910HIGH7.8 IBM Security Guardium 11.3 could allow a local user to escalate their privileges due to improper permission controls. ...
CVE-2022-43908MEDIUM6.5 IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validat...
CVE-2022-47421MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Repute InfoSystems ARMember (free), Repute InfoSystems...
CVE-2022-47085HIGH7.5An issue was discovered in ostree before 2022.7 allows attackers to cause a denial of service or other unspecified impac...
CVE-2022-41409HIGH7.5Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecif...
CVE-2022-34155HIGH8.8Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authenticati...
CVE-2022-33065HIGH7.8Multiple signed integers overflow in function au_read_header in src/au.c and in functions mat4_open and mat4_read_header...
CVE-2022-33064HIGH7.8An off-by-one error in function wav_read_header in src/wav.c in Libsndfile 1.1.0, results in a write out of bound, which...
CVE-2022-26563HIGH8.8An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to i...
CVE-2022-47169HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in StaxWP Visibility Logic for Elementor plugin <= 2.3.4 versions.
CVE-2022-46857HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in SiteAlert plugin <= 1.9.7 versions.
CVE-2022-45828HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in NooTheme Noo Timetable plugin <= 2.1.3 versions.
CVE-2022-4146CRITICAL9.8Expression Language Injection vulnerability in Hitachi Replication Manager on Windows, Linux, Solaris allows Code Inject...
CVE-2022-30858MEDIUM6.5An issue was discovered in ngiflib 0.4. There is SEGV in SDL_LoadAnimatedGif when use SDLaffgif. poc : ./SDLaffgif CA_fi...
CVE-2022-38062HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Metagauss Download Theme plugin <= 1.0.9 versions.
CVE-2022-36424HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Nikola Loncar Easy Appointments plugin <= 3.11.9 versions.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now