2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20364 | HIGH | 7.8 | 0.1% | Sep 14, 2022 | In sysmmu_unmap of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local ... |
| CVE-2022-3202 | HIGH | 7.1 | 0.2% | Sep 14, 2022 | A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This coul... |
| CVE-2022-40674 | HIGH | 8.1 | 1.7% | Sep 14, 2022 | libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. |
| CVE-2022-40673 | HIGH | 7.8 | 0.4% | Sep 14, 2022 | KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache. |
| CVE-2022-37140 | HIGH | 8 | 1.3% | Sep 14, 2022 | PayMoney 3.3 is vulnerable to Client Side Remote Code Execution (RCE). The vulnerability exists on the reply ticket func... |
| CVE-2022-36667 | HIGH | 8.8 | 24.4% | Sep 14, 2022 | Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file... |
| CVE-2022-38769 | HIGH | 7.5 | 0.8% | Sep 13, 2022 | The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch cleartext... |
| CVE-2022-38305 | HIGH | 8.8 | 0.9% | Sep 13, 2022 | AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. Th... |
| CVE-2022-37190 | HIGH | 8.8 | 45.8% | Sep 13, 2022 | CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and... |
| CVE-2022-38633 | HIGH | 7.8 | 0.2% | Sep 13, 2022 | Genymotion Desktop v3.2.1 was discovered to contain a DLL hijacking vulnerability which allows attackers to escalate pri... |
| CVE-2022-35582 | HIGH | 8.8 | 0.7% | Sep 13, 2022 | Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating sy... |
| CVE-2022-34102 | HIGH | 8.8 | 0.9% | Sep 13, 2022 | Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39,... |
| CVE-2022-34101 | HIGH | 7.8 | 0.3% | Sep 13, 2022 | A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place... |
| CVE-2022-31322 | HIGH | 7.8 | 0.3% | Sep 13, 2022 | Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges via overwriting files us... |
| CVE-2022-40623 | HIGH | 8.8 | 0.5% | Sep 13, 2022 | The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 does not utilize anti-CSRF tokens, which, ... |
| CVE-2022-40622 | HIGH | 8.8 | 0.7% | Sep 13, 2022 | The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and doe... |
| CVE-2022-40621 | HIGH | 7.5 | 0.7% | Sep 13, 2022 | Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP... |
| CVE-2022-39821 | HIGH | 7.5 | 0.6% | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The we... |
| CVE-2022-39819 | HIGH | 8.8 | 1.4% | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execut... |
| CVE-2022-39817 | HIGH | 8.8 | 0.7% | Sep 13, 2022 | In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker.... |
| CVE-2022-38495 | HIGH | 7.8 | 0.3% | Sep 13, 2022 | LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c. |
| CVE-2022-38306 | HIGH | 7.8 | 0.3% | Sep 13, 2022 | LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc. |
| CVE-2022-36768 | HIGH | 7.8 | 0.2% | Sep 13, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout c... |
| CVE-2022-34356 | HIGH | 7.8 | 0.2% | Sep 13, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel... |
| CVE-2022-3182 | HIGH | 7 | 0.2% | Sep 13, 2022 | Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earl... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now