2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39843 | HIGH | 7.8 | 0.4% | Sep 5, 2022 | 123elf Lotus 1-2-3 before 1.0.0rc3 for Linux, and Lotus 1-2-3 R3 for UNIX and other platforms through 9.8.2, allow attac... |
| CVE-2022-39051 | HIGH | 8.8 | 0.7% | Sep 5, 2022 | Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverif... |
| CVE-2022-39832 | HIGH | 7.8 | 0.5% | Sep 5, 2022 | An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/ps... |
| CVE-2022-39831 | HIGH | 7.8 | 0.5% | Sep 5, 2022 | An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in util... |
| CVE-2022-39830 | HIGH | 7.5 | 1.0% | Sep 5, 2022 | sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_public_key_affine_coo... |
| CVE-2022-39829 | HIGH | 7.5 | 1.0% | Sep 5, 2022 | There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the retu... |
| CVE-2022-39828 | HIGH | 7.5 | 1.0% | Sep 5, 2022 | sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_private_key, leading ... |
| CVE-2022-39824 | HIGH | 8.9 | 0.9% | Sep 5, 2022 | Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code... |
| CVE-2022-3099 | HIGH | 7.8 | 0.5% | Sep 3, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0360. |
| CVE-2022-36754 | HIGH | 7.2 | 0.7% | Sep 2, 2022 | Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/deb... |
| CVE-2022-31176 | HIGH | 8.1 | 0.9% | Sep 2, 2022 | Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headles... |
| CVE-2022-31196 | HIGH | 7.5 | 0.8% | Sep 2, 2022 | Databasir is a database metadata management platform. Databasir <= 1.06 has Server-Side Request Forgery (SSRF) vulnerabi... |
| CVE-2022-31152 | HIGH | 7.5 | 0.9% | Sep 2, 2022 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specificatio... |
| CVE-2022-3065 | HIGH | 7.5 | 1.0% | Sep 2, 2022 | Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8. |
| CVE-2022-36071 | HIGH | 8.1 | 0.4% | Sep 2, 2022 | SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support... |
| CVE-2022-34382 | HIGH | 7.8 | 0.2% | Sep 2, 2022 | Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vuln... |
| CVE-2022-34369 | HIGH | 7.5 | 0.5% | Sep 2, 2022 | Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertio... |
| CVE-2022-36078 | HIGH | 7.5 | 0.9% | Sep 2, 2022 | Binary provides encoding/decoding in Borsh and other formats. The vulnerability is a memory allocation vulnerability tha... |
| CVE-2022-36076 | HIGH | 7.5 | 0.4% | Sep 2, 2022 | NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unne... |
| CVE-2022-37458 | HIGH | 7.2 | 1.1% | Sep 2, 2022 | Discourse through 2.8.7 allows admins to send invitations to arbitrary email addresses at an unlimited rate. |
| CVE-2022-25680 | HIGH | 7.8 | 0.1% | Sep 2, 2022 | Memory corruption in multimedia due to buffer overflow while processing count variable from client in Snapdragon Auto |
| CVE-2022-22106 | HIGH | 7.8 | 0.1% | Sep 2, 2022 | Memory corruption in multimedia due to improper length check while copying the data in Snapdragon Auto |
| CVE-2022-22104 | HIGH | 7.8 | 0.1% | Sep 2, 2022 | Memory corruption in multimedia due to improper check on the messages received. in Snapdragon Auto |
| CVE-2022-22102 | HIGH | 7.8 | 0.1% | Sep 2, 2022 | Memory corruption in multimedia due to incorrect type conversion while adding data in Snapdragon Auto |
| CVE-2022-22100 | HIGH | 7.8 | 0.1% | Sep 2, 2022 | Memory corruption in multimedia due to improper check on received export descriptors in Snapdragon Auto |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now