2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-2529HIGH7.5sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attack...
CVE-2022-24373HIGH7.5The package react-native-reanimated before 3.0.0-rc.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due...
CVE-2022-21222HIGH7.5The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of ins...
CVE-2022-41828HIGH8.1In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Facto...
CVE-2022-3364HIGH7.5Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.
CVE-2022-40472HIGH8ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vu...
CVE-2022-36066HIGH7.2Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.be...
CVE-2022-39168HIGH7.5IBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID...
CVE-2022-39252HIGH7.5matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encr...
CVE-2022-38732HIGH7.5SnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which could allow certain typ...
CVE-2022-40407HIGH8.8A zip slip vulnerability in the file upload function of Chamilo v1.11 allows attackers to execute arbitrary code via a c...
CVE-2022-40890HIGH7.5A vulnerability in /src/amf/amf-context.c in Open5GS 2.4.10 and earlier leads to AMF denial of service.
CVE-2022-39250HIGH7.5Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0...
CVE-2022-40126HIGH7.8A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privi...
CVE-2022-3352HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0614.
CVE-2022-40279HIGH7.5An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). l2_packet_receive_timeout in wpa_supplicant/sr...
CVE-2022-40278HIGH7.5An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisio...
CVE-2022-38222HIGH7.8There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by s...
CVE-2022-1718HIGH7.5The trudesk application allows large characters to insert in the input field "Full Name" on the signup field which can a...
CVE-2022-40048HIGH7.2Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function.
CVE-2022-39173HIGH7.5In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an a...
CVE-2022-40710HIGH7.8A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could...
CVE-2022-39263HIGH8.1`@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next....
CVE-2022-39257HIGH7.5Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker coopera...
CVE-2022-39255HIGH7.5Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker coopera...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now