2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36798 | HIGH | 8.8 | 0.3% | Sep 23, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Topdigitaltrends Mega Addons For WPBakery Page Builder plugin <= 4.2.... |
| CVE-2022-35257 | HIGH | 7.8 | 0.2% | Sep 23, 2022 | A local privilege escalation vulnerability in UI Desktop for Windows (Version 0.55.1.2 and earlier) allows a malicious a... |
| CVE-2022-27492 | HIGH | 7.8 | 0.5% | Sep 23, 2022 | An integer underflow in WhatsApp could have caused remote code execution when receiving a crafted video file. |
| CVE-2022-2347 | HIGH | 7.1 | 0.6% | Sep 23, 2022 | There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DF... |
| CVE-2022-2566 | HIGH | 7.8 | 0.6% | Sep 23, 2022 | A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points... |
| CVE-2022-38936 | HIGH | 7.5 | 0.7% | Sep 23, 2022 | An issue has been found in PBC through 2022-8-27. A SEGV issue detected in the function pbc_wmessage_integer in src/wmes... |
| CVE-2022-39238 | HIGH | 8.8 | 0.4% | Sep 23, 2022 | Arvados is an open source platform for managing and analyzing biomedical big data. In versions prior to 2.4.3, when usin... |
| CVE-2022-41322 | HIGH | 7.8 | 0.5% | Sep 23, 2022 | In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code e... |
| CVE-2022-40298 | HIGH | 8.8 | 0.6% | Sep 23, 2022 | Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation ... |
| CVE-2022-30426 | HIGH | 7.8 | 0.4% | Sep 23, 2022 | There is a stack buffer overflow vulnerability, which could lead to arbitrary code execution in UEFI DXE driver on some ... |
| CVE-2022-37234 | HIGH | 7.8 | 0.5% | Sep 22, 2022 | Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow... |
| CVE-2022-34026 | HIGH | 7.5 | 1.5% | Sep 22, 2022 | ICEcoder v8.1 allows attackers to execute a directory traversal. |
| CVE-2022-40935 | HIGH | 7.2 | 0.8% | Sep 22, 2022 | Online Pet Shop We App v1.0 is vulnerable to SQL Injection via /pet_shop/classes/Master.php?f=delete_category,id. |
| CVE-2022-40934 | HIGH | 7.2 | 0.8% | Sep 22, 2022 | Online Pet Shop We App v1.0 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_sub_category,id |
| CVE-2022-40933 | HIGH | 7.2 | 0.8% | Sep 22, 2022 | Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,... |
| CVE-2022-40932 | HIGH | 7.2 | 0.9% | Sep 22, 2022 | In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "galle... |
| CVE-2022-35408 | HIGH | 8.2 | 0.3% | Sep 22, 2022 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM callout vulnerability in the SMM driver ... |
| CVE-2022-40146 | HIGH | 7.5 | 6.1% | Sep 22, 2022 | Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files usin... |
| CVE-2022-1941 | HIGH | 7.5 | 1.2% | Sep 22, 2022 | A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3... |
| CVE-2022-40447 | HIGH | 7.2 | 0.9% | Sep 22, 2022 | ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php. |
| CVE-2022-40446 | HIGH | 7.2 | 0.8% | Sep 22, 2022 | ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&group... |
| CVE-2022-3256 | HIGH | 7.8 | 0.5% | Sep 22, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0530. |
| CVE-2022-40705 | HIGH | 7.5 | 1.4% | Sep 22, 2022 | An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an atta... |
| CVE-2022-28981 | HIGH | 7.5 | 1.1% | Sep 22, 2022 | Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote atta... |
| CVE-2022-39224 | HIGH | 7.8 | 1.6% | Sep 21, 2022 | Arr-pm is an RPM reader/writer library written in Ruby. Versions prior to 0.0.12 are subject to OS command injection res... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now