2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-32574MEDIUM6.5A double-free vulnerability exists in the web interface /action/ipcamSetParamPost functionality of Abode Systems, Inc. i...
CVE-2022-2762MEDIUM6.5The AdminPad WordPress plugin before 2.2 does not have CSRF check when updating admin's note, allowing attackers to make...
CVE-2022-27622MEDIUM4.3Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) b...
CVE-2022-43677MEDIUM5.5In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in aper.G...
CVE-2022-41799MEDIUM6.5Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) all...
CVE-2022-41797MEDIUM6.5Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 ...
CVE-2022-40690MEDIUM5.4Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to injec...
CVE-2022-3676MEDIUM6.5In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode...
CVE-2022-38117MEDIUM6.1Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can...
CVE-2022-36368MEDIUM4.8Multiple stored cross-site scripting vulnerabilities in the web user interface of IPFire versions prior to 2.27 allows a...
CVE-2022-39272MEDIUM4.3Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a De...
CVE-2022-39259MEDIUM5.5jadx is a set of command line and GUI tools for producing Java source code from Android Dex and Apk files. versions prio...
CVE-2022-3646MEDIUM4.3A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function ni...
CVE-2022-34438MEDIUM6.7Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malici...
CVE-2022-34437MEDIUM6.7Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privileged local malicious...
CVE-2022-31239MEDIUM4.4Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log...
CVE-2022-41638MEDIUM5.4Auth. Stored Cross-Site Scripting (XSS) in Pop-Up Chop Chop plugin <= 2.1.7 on WordPress.
CVE-2022-40311MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) in Fatcat Apps Analytics Cat plugin <= 1.0.9 on WordPress.
CVE-2022-3627MEDIUM6.5LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, ...
CVE-2022-3626MEDIUM6.5LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections...
CVE-2022-3599MEDIUM6.5LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a de...
CVE-2022-3598MEDIUM6.5LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attacke...
CVE-2022-3597MEDIUM6.5LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, ...
CVE-2022-3570MEDIUM5.5Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe ...
CVE-2022-27494MEDIUM5.4Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely acce...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now