2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-0559CRITICAL9.8Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
CVE-2022-25236CRITICAL9.8xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace...
CVE-2022-25235CRITICAL9.8xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UT...
CVE-2022-22770CRITICAL9.8The Web Server component of TIBCO Software Inc.'s TIBCO AuditSafe contains an easily exploitable vulnerability that allo...
CVE-2022-25139CRITICAL9.8njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.
CVE-2022-24705CRITICAL9.8The rad_packet_recv function in radius/packet.c suffers from a memcpy buffer overflow, resulting in an overly-large recv...
CVE-2022-24704CRITICAL9.8The rad_packet_recv function in opt/src/accel-pppd/radius/packet.c suffers from a buffer overflow vulnerability, whereby...
CVE-2022-23992CRITICAL9.8XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validat...
CVE-2022-0582CRITICAL9.8Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of servic...
CVE-2022-24206CRITICAL9.8Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in /mobile_seal/get_seal.php via the DEVICE_LI...
CVE-2022-23902CRITICAL9.8Tongda2000 v11.10 was discovered to contain a SQL injection vulnerability in export_data.php via the d_name parameter.
CVE-2022-23390CRITICAL9.8An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files.
CVE-2022-23389CRITICAL9.8PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
CVE-2022-23337CRITICAL9.8DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parame...
CVE-2022-23336CRITICAL9.8S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.
CVE-2022-23335CRITICAL9.8Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in language_general.class.php via doModifyParamet...
CVE-2022-22295CRITICAL9.8Metinfo v7.5.0 was discovered to contain a SQL injection vulnerability in parameter_admin.class.php via the table_para p...
CVE-2022-24988CRITICAL9.8In galois_2p8 before 0.1.2, PrimitivePolynomialField::new has an off-by-one buffer overflow for a vector.
CVE-2022-24977CRITICAL9.8ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or ima...
CVE-2022-24976CRITICAL9.1Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC...
CVE-2022-0570CRITICAL9.8Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.
CVE-2022-0290CRITICAL9.6Use after free in Site isolation in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to potentially perform...
CVE-2022-0097CRITICAL9.6Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user...
CVE-2022-24927CRITICAL9.8Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execu...
CVE-2022-23425CRITICAL9.8Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS sign...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now