2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38932 | HIGH | 7.8 | 0.3% | Sep 27, 2022 | readelf in ToaruOS 2.0.1 has a global overflow allowing RCE when parsing a crafted ELF file. |
| CVE-2022-37209 | HIGH | 8.8 | 1.1% | Sep 27, 2022 | JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters... |
| CVE-2022-37193 | HIGH | 7.4 | 0.5% | Sep 27, 2022 | Chipolo ONE Bluetooth tracker (2020) Chipolo iOS app version 4.13.0 is vulnerable to Incorrect Access Control. Chipolo d... |
| CVE-2022-34326 | HIGH | 7.5 | 0.6% | Sep 27, 2022 | In ambiot amb1_sdk (aka SDK for Ameba1) before 2022-06-20 on Realtek RTL8195AM devices before 284241d70308ff2519e40afd7b... |
| CVE-2022-31367 | HIGH | 8.8 | 1.3% | Sep 27, 2022 | Strapi before 3.6.10 and 4.x before 4.1.10 mishandles hidden attributes within admin API responses. |
| CVE-2022-39258 | HIGH | 8.2 | 0.6% | Sep 27, 2022 | mailcow is a mailserver suite. A vulnerability innversions prior to 2022-09 allows an attacker to craft a custom Swagger... |
| CVE-2022-39256 | HIGH | 8 | 1.2% | Sep 27, 2022 | Orckestra C1 CMS is a .NET based Web Content Management System. A vulnerability in versions prior to 6.13 allows remote ... |
| CVE-2022-3298 | HIGH | 7.5 | 0.9% | Sep 26, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.4.8. |
| CVE-2022-40099 | HIGH | 7.2 | 0.8% | Sep 26, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2022-40098 | HIGH | 7.2 | 0.8% | Sep 26, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2022-40097 | HIGH | 7.2 | 0.8% | Sep 26, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramet... |
| CVE-2022-3290 | HIGH | 7.5 | 0.7% | Sep 26, 2022 | Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8. |
| CVE-2022-3272 | HIGH | 7.5 | 1.4% | Sep 26, 2022 | Improper Handling of Length Parameter Inconsistency in GitHub repository ikus060/rdiffweb prior to 2.4.8. |
| CVE-2022-22058 | HIGH | 7.8 | 0.2% | Sep 26, 2022 | Memory corruption due to use after free issue in kernel while processing ION handles in Snapdragon Auto, Snapdragon Comp... |
| CVE-2022-40784 | HIGH | 8.8 | 0.9% | Sep 26, 2022 | Unlimited strcpy on user input when setting a locale file leads to stack buffer overflow in mIPC camera firmware 5.3.1.2... |
| CVE-2022-40043 | HIGH | 8.8 | 1.1% | Sep 26, 2022 | Centreon v20.10.18 was discovered to contain a SQL injection vulnerability via the esc_name (Escalation Name) parameter ... |
| CVE-2022-3200 | HIGH | 8.8 | 0.7% | Sep 26, 2022 | Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially expl... |
| CVE-2022-3199 | HIGH | 8.8 | 1.9% | Sep 26, 2022 | Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap ... |
| CVE-2022-3198 | HIGH | 8.8 | 0.6% | Sep 26, 2022 | Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2022-3197 | HIGH | 8.8 | 0.6% | Sep 26, 2022 | Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2022-3196 | HIGH | 8.8 | 0.8% | Sep 26, 2022 | Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2022-3195 | HIGH | 8.8 | 1.0% | Sep 26, 2022 | Out of bounds write in Storage in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to perform an out of b... |
| CVE-2022-3071 | HIGH | 8.8 | 0.4% | Sep 26, 2022 | Use after free in Tab Strip in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who c... |
| CVE-2022-3058 | HIGH | 8.8 | 0.6% | Sep 26, 2022 | Use after free in Sign-In Flow in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to... |
| CVE-2022-3055 | HIGH | 8.8 | 0.7% | Sep 26, 2022 | Use after free in Passwords in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to en... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now