2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-20364HIGH7.8In sysmmu_unmap of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local ...
CVE-2022-3202HIGH7.1A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This coul...
CVE-2022-40674HIGH8.1libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
CVE-2022-40673HIGH7.8KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.
CVE-2022-37140HIGH8PayMoney 3.3 is vulnerable to Client Side Remote Code Execution (RCE). The vulnerability exists on the reply ticket func...
CVE-2022-36667HIGH8.8Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file...
CVE-2022-38769HIGH7.5The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote attackers to fetch cleartext...
CVE-2022-38305HIGH8.8AeroCMS v0.0.1 was discovered to contain an arbitrary file upload vulnerability via the component /admin/profile.php. Th...
CVE-2022-37190HIGH8.8CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and...
CVE-2022-38633HIGH7.8Genymotion Desktop v3.2.1 was discovered to contain a DLL hijacking vulnerability which allows attackers to escalate pri...
CVE-2022-35582HIGH8.8Penta Security Systems Inc WAPPLES 4.0.*, 5.0.0.*, 5.0.12.* are vulnerable to Incorrect Access Control. The operating sy...
CVE-2022-34102HIGH8.8Insufficient access control vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39,...
CVE-2022-34101HIGH7.8A vulnerability was discovered in the Crestron AirMedia Windows Application, version 4.3.1.39, in which a user can place...
CVE-2022-31322HIGH7.8Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges via overwriting files us...
CVE-2022-40623HIGH8.8The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 does not utilize anti-CSRF tokens, which, ...
CVE-2022-40622HIGH8.8The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and doe...
CVE-2022-40621HIGH7.5Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP...
CVE-2022-39821HIGH7.5In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The we...
CVE-2022-39819HIGH8.8In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execut...
CVE-2022-39817HIGH8.8In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker....
CVE-2022-38495HIGH7.8LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c.
CVE-2022-38306HIGH7.8LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc.
CVE-2022-36768HIGH7.8IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout c...
CVE-2022-34356HIGH7.8IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel...
CVE-2022-3182HIGH7Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earl...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now