2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2529 | HIGH | 7.5 | 0.8% | Sep 30, 2022 | sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attack... |
| CVE-2022-24373 | HIGH | 7.5 | 1.2% | Sep 30, 2022 | The package react-native-reanimated before 3.0.0-rc.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due... |
| CVE-2022-21222 | HIGH | 7.5 | 1.4% | Sep 30, 2022 | The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of ins... |
| CVE-2022-41828 | HIGH | 8.1 | 1.5% | Sep 29, 2022 | In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Facto... |
| CVE-2022-3364 | HIGH | 7.5 | 1.0% | Sep 29, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3. |
| CVE-2022-40472 | HIGH | 8 | 0.9% | Sep 29, 2022 | ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vu... |
| CVE-2022-36066 | HIGH | 7.2 | 1.6% | Sep 29, 2022 | Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be... |
| CVE-2022-39168 | HIGH | 7.5 | 0.7% | Sep 29, 2022 | IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID... |
| CVE-2022-39252 | HIGH | 7.5 | 0.5% | Sep 29, 2022 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encr... |
| CVE-2022-38732 | HIGH | 7.5 | 0.6% | Sep 29, 2022 | SnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which could allow certain typ... |
| CVE-2022-40407 | HIGH | 8.8 | 1.2% | Sep 29, 2022 | A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a c... |
| CVE-2022-40890 | HIGH | 7.5 | 0.9% | Sep 29, 2022 | A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service. |
| CVE-2022-39250 | HIGH | 7.5 | 0.9% | Sep 29, 2022 | Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0... |
| CVE-2022-40126 | HIGH | 7.8 | 0.3% | Sep 29, 2022 | A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privi... |
| CVE-2022-3352 | HIGH | 7.8 | 0.5% | Sep 29, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0614. |
| CVE-2022-40279 | HIGH | 7.5 | 1.1% | Sep 29, 2022 | An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). l2_packet_receive_timeout in wpa_supplicant/sr... |
| CVE-2022-40278 | HIGH | 7.5 | 1.3% | Sep 29, 2022 | An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisio... |
| CVE-2022-38222 | HIGH | 7.8 | 0.4% | Sep 29, 2022 | There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by s... |
| CVE-2022-1718 | HIGH | 7.5 | 1.0% | Sep 29, 2022 | The trudesk application allows large characters to insert in the input field "Full Name" on the signup field which can a... |
| CVE-2022-40048 | HIGH | 7.2 | 2.3% | Sep 29, 2022 | Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function. |
| CVE-2022-39173 | HIGH | 7.5 | 4.3% | Sep 29, 2022 | In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an a... |
| CVE-2022-40710 | HIGH | 7.8 | 0.2% | Sep 28, 2022 | A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could... |
| CVE-2022-39263 | HIGH | 8.1 | 0.6% | Sep 28, 2022 | `@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next.... |
| CVE-2022-39257 | HIGH | 7.5 | 0.7% | Sep 28, 2022 | Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker coopera... |
| CVE-2022-39255 | HIGH | 7.5 | 0.7% | Sep 28, 2022 | Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker coopera... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now