2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-39843HIGH7.8123elf Lotus 1-2-3 before 1.0.0rc3 for Linux, and Lotus 1-2-3 R3 for UNIX and other platforms through 9.8.2, allow attac...
CVE-2022-39051HIGH8.8Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverif...
CVE-2022-39832HIGH7.8An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/ps...
CVE-2022-39831HIGH7.8An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in util...
CVE-2022-39830HIGH7.5sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_public_key_affine_coo...
CVE-2022-39829HIGH7.5There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the retu...
CVE-2022-39828HIGH7.5sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_private_key, leading ...
CVE-2022-39824HIGH8.9Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code...
CVE-2022-3099HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0360.
CVE-2022-36754HIGH7.2Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/deb...
CVE-2022-31176HIGH8.1Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headles...
CVE-2022-31196HIGH7.5Databasir is a database metadata management platform. Databasir <= 1.06 has Server-Side Request Forgery (SSRF) vulnerabi...
CVE-2022-31152HIGH7.5Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specificatio...
CVE-2022-3065HIGH7.5Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8.
CVE-2022-36071HIGH8.1SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support...
CVE-2022-34382HIGH7.8Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vuln...
CVE-2022-34369HIGH7.5Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertio...
CVE-2022-36078HIGH7.5Binary provides encoding/decoding in Borsh and other formats. The vulnerability is a memory allocation vulnerability tha...
CVE-2022-36076HIGH7.5NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unne...
CVE-2022-37458HIGH7.2Discourse through 2.8.7 allows admins to send invitations to arbitrary email addresses at an unlimited rate.
CVE-2022-25680HIGH7.8Memory corruption in multimedia due to buffer overflow while processing count variable from client in Snapdragon Auto
CVE-2022-22106HIGH7.8Memory corruption in multimedia due to improper length check while copying the data in Snapdragon Auto
CVE-2022-22104HIGH7.8Memory corruption in multimedia due to improper check on the messages received. in Snapdragon Auto
CVE-2022-22102HIGH7.8Memory corruption in multimedia due to incorrect type conversion while adding data in Snapdragon Auto
CVE-2022-22100HIGH7.8Memory corruption in multimedia due to improper check on received export descriptors in Snapdragon Auto

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now