2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38118 | HIGH | 8.8 | 1.3% | Aug 30, 2022 | OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user p... |
| CVE-2022-25887 | HIGH | 7.5 | 1.1% | Aug 30, 2022 | The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure gl... |
| CVE-2022-25857 | HIGH | 7.5 | 2.1% | Aug 30, 2022 | The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested de... |
| CVE-2022-24107 | HIGH | 7.8 | 0.3% | Aug 30, 2022 | Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc. |
| CVE-2022-24106 | HIGH | 7.8 | 0.3% | Aug 30, 2022 | In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the fi... |
| CVE-2022-38784 | HIGH | 7.8 | 0.6% | Aug 30, 2022 | Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg... |
| CVE-2022-38625 | HIGH | 8.8 | 0.5% | Aug 29, 2022 | Patlite NH-FB v1.46 and below was discovered to contain insufficient firmware validation during the upgrade firmware fil... |
| CVE-2022-37681 | HIGH | 7.5 | 1.0% | Aug 29, 2022 | Hitachi Kokusai Electric Newtork products for monitoring system (Camera, Decoder and Encoder) and below allows attckers ... |
| CVE-2022-37680 | HIGH | 7.5 | 0.7% | Aug 29, 2022 | An improper authentication for critical function issue in Hitachi Kokusai Electric Network products for monitoring syste... |
| CVE-2022-38772 | HIGH | 8.8 | 77.6% | Aug 29, 2022 | Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils... |
| CVE-2022-37177 | HIGH | 7.5 | 0.4% | Aug 29, 2022 | HireVue Hiring Platform V1.0 suffers from Use of a Broken or Risky Cryptographic Algorithm. NOTE: this is disputed by th... |
| CVE-2022-36036 | HIGH | 7.8 | 0.4% | Aug 29, 2022 | mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection ... |
| CVE-2022-2559 | HIGH | 7.2 | 0.9% | Aug 29, 2022 | The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters befo... |
| CVE-2022-2261 | HIGH | 7.2 | 1.1% | Aug 29, 2022 | The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require... |
| CVE-2022-1123 | HIGH | 7.2 | 1.0% | Aug 29, 2022 | The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitiz... |
| CVE-2022-36034 | HIGH | 7.5 | 0.8% | Aug 29, 2022 | nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of `{{` and with many repetitions o... |
| CVE-2022-27558 | HIGH | 7.5 | 0.5% | Aug 29, 2022 | HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced ... |
| CVE-2022-27547 | HIGH | 7.4 | 0.4% | Aug 29, 2022 | HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to tr... |
| CVE-2022-36200 | HIGH | 7.5 | 1.8% | Aug 29, 2022 | In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed. |
| CVE-2022-2961 | HIGH | 7 | 0.3% | Aug 29, 2022 | A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition... |
| CVE-2022-1199 | HIGH | 7.5 | 1.5% | Aug 29, 2022 | A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio... |
| CVE-2022-1117 | HIGH | 8.4 | 0.3% | Aug 29, 2022 | A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime lin... |
| CVE-2022-1043 | HIGH | 8.8 | 3.7% | Aug 29, 2022 | A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows an attacker with a local account to cor... |
| CVE-2022-0934 | HIGH | 7.5 | 1.4% | Aug 29, 2022 | A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a cr... |
| CVE-2022-0850 | HIGH | 7.1 | 0.4% | Aug 29, 2022 | A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now