2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34917 | HIGH | 7.5 | 1.2% | Sep 20, 2022 | A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability all... |
| CVE-2022-39958 | HIGH | 7.5 | 0.9% | Sep 20, 2022 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and und... |
| CVE-2022-39957 | HIGH | 7.5 | 0.8% | Sep 20, 2022 | The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept heade... |
| CVE-2022-38532 | HIGH | 7.8 | 0.5% | Sep 19, 2022 | Micro-Star International Co., Ltd MSI Center 1.0.50.0 was discovered to contain a vulnerability in the component C_Featu... |
| CVE-2022-38351 | HIGH | 8.8 | 0.9% | Sep 19, 2022 | A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administra... |
| CVE-2022-28204 | HIGH | 7.5 | 0.8% | Sep 19, 2022 | A denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWha... |
| CVE-2022-28203 | HIGH | 7.5 | 1.1% | Sep 19, 2022 | A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. Whe... |
| CVE-2022-3239 | HIGH | 7.8 | 0.2% | Sep 19, 2022 | A flaw use after free in the Linux kernel video4linux driver was found in the way user triggers em28xx_usb_probe() for t... |
| CVE-2022-38576 | HIGH | 7.2 | 0.8% | Sep 19, 2022 | Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/de... |
| CVE-2022-2995 | HIGH | 7.1 | 0.4% | Sep 19, 2022 | Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclos... |
| CVE-2022-23766 | HIGH | 8.8 | 0.5% | Sep 19, 2022 | An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order ... |
| CVE-2022-40608 | HIGH | 7.5 | 1.6% | Sep 19, 2022 | IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the t... |
| CVE-2022-40143 | HIGH | 7.3 | 0.4% | Sep 19, 2022 | A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service ... |
| CVE-2022-40142 | HIGH | 7.8 | 0.3% | Sep 19, 2022 | A security link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a... |
| CVE-2022-40141 | HIGH | 7.5 | 1.1% | Sep 19, 2022 | A vulnerability in Trend Micro Apex One and Apex One as a Service could allow an attacker to intercept and decode certai... |
| CVE-2022-40139 | HIGH | 7.2 | 2.9% | Sep 19, 2022 | Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One a... |
| CVE-2022-38764 | HIGH | 7.8 | 0.2% | Sep 19, 2022 | A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieg... |
| CVE-2022-34893 | HIGH | 7.8 | 0.3% | Sep 19, 2022 | Trend Micro Security 2022 (consumer) has a link following vulnerability where an attacker with lower privileges could ma... |
| CVE-2022-40468 | HIGH | 7.5 | 1.4% | Sep 19, 2022 | Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used.... |
| CVE-2022-38333 | HIGH | 7.5 | 1.0% | Sep 19, 2022 | Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(... |
| CVE-2022-40978 | HIGH | 7.8 | 0.2% | Sep 19, 2022 | The installer of JetBrains IntelliJ IDEA before 2022.2.2 was vulnerable to EXE search order hijacking |
| CVE-2022-38618 | HIGH | 8.8 | 0.8% | Sep 19, 2022 | SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id88, UserForm:j_id9... |
| CVE-2022-38577 | HIGH | 8.8 | 1.7% | Sep 19, 2022 | ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability a... |
| CVE-2022-37700 | HIGH | 7.5 | 2.8% | Sep 19, 2022 | Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component ... |
| CVE-2022-35708 | HIGH | 7.8 | 0.6% | Sep 19, 2022 | Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerab... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now