2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32574 | MEDIUM | 6.5 | 1.5% | Oct 25, 2022 | A double-free vulnerability exists in the web interface /action/ipcamSetParamPost functionality of Abode Systems, Inc. i... |
| CVE-2022-2762 | MEDIUM | 6.5 | 0.3% | Oct 25, 2022 | The AdminPad WordPress plugin before 2.2 does not have CSRF check when updating admin's note, allowing attackers to make... |
| CVE-2022-27622 | MEDIUM | 4.3 | 0.7% | Oct 25, 2022 | Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) b... |
| CVE-2022-43677 | MEDIUM | 5.5 | 0.7% | Oct 24, 2022 | In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in aper.G... |
| CVE-2022-41799 | MEDIUM | 6.5 | 0.8% | Oct 24, 2022 | Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) all... |
| CVE-2022-41797 | MEDIUM | 6.5 | 0.9% | Oct 24, 2022 | Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 ... |
| CVE-2022-40690 | MEDIUM | 5.4 | 0.7% | Oct 24, 2022 | Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to injec... |
| CVE-2022-3676 | MEDIUM | 6.5 | 0.6% | Oct 24, 2022 | In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode... |
| CVE-2022-38117 | MEDIUM | 6.1 | 0.3% | Oct 24, 2022 | Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can... |
| CVE-2022-36368 | MEDIUM | 4.8 | 0.7% | Oct 24, 2022 | Multiple stored cross-site scripting vulnerabilities in the web user interface of IPFire versions prior to 2.27 allows a... |
| CVE-2022-39272 | MEDIUM | 4.3 | 0.6% | Oct 22, 2022 | Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a De... |
| CVE-2022-39259 | MEDIUM | 5.5 | 0.3% | Oct 21, 2022 | jadx is a set of command line and GUI tools for producing Java source code from Android Dex and Apk files. versions prio... |
| CVE-2022-3646 | MEDIUM | 4.3 | 0.8% | Oct 21, 2022 | A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function ni... |
| CVE-2022-34438 | MEDIUM | 6.7 | 0.2% | Oct 21, 2022 | Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malici... |
| CVE-2022-34437 | MEDIUM | 6.7 | 0.5% | Oct 21, 2022 | Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privileged local malicious... |
| CVE-2022-31239 | MEDIUM | 4.4 | 0.2% | Oct 21, 2022 | Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, and 9.3.0.6, contain sensitive data in log... |
| CVE-2022-41638 | MEDIUM | 5.4 | 0.4% | Oct 21, 2022 | Auth. Stored Cross-Site Scripting (XSS) in Pop-Up Chop Chop plugin <= 2.1.7 on WordPress. |
| CVE-2022-40311 | MEDIUM | 4.8 | 0.4% | Oct 21, 2022 | Auth. (admin+) Stored Cross-Site Scripting (XSS) in Fatcat Apps Analytics Cat plugin <= 1.0.9 on WordPress. |
| CVE-2022-3627 | MEDIUM | 6.5 | 1.0% | Oct 21, 2022 | LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, ... |
| CVE-2022-3626 | MEDIUM | 6.5 | 0.9% | Oct 21, 2022 | LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in libtiff/tif_unix.c:340 when called from processCropSelections... |
| CVE-2022-3599 | MEDIUM | 6.5 | 0.9% | Oct 21, 2022 | LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a de... |
| CVE-2022-3598 | MEDIUM | 6.5 | 0.9% | Oct 21, 2022 | LibTIFF 4.4.0 has an out-of-bounds write in extractContigSamplesShifted24bits in tools/tiffcrop.c:3604, allowing attacke... |
| CVE-2022-3597 | MEDIUM | 6.5 | 0.9% | Oct 21, 2022 | LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemcpy in libtiff/tif_unix.c:346 when called from extractImageSection, ... |
| CVE-2022-3570 | MEDIUM | 5.5 | 0.5% | Oct 21, 2022 | Multiple heap buffer overflows in tiffcrop.c utility in libtiff library Version 4.4.0 allows attacker to trigger unsafe ... |
| CVE-2022-27494 | MEDIUM | 5.4 | 0.6% | Oct 21, 2022 | Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely acce... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now