2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-38118HIGH8.8OAKlouds Portal website’s Meeting Room has insufficient validation for user input. A remote attacker with general user p...
CVE-2022-25887HIGH7.5The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure gl...
CVE-2022-25857HIGH7.5The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested de...
CVE-2022-24107HIGH7.8Xpdf prior to 4.04 lacked an integer overflow check in JPXStream.cc.
CVE-2022-24106HIGH7.8In Xpdf prior to 4.04, the DCT (JPEG) decoder was incorrectly allowing the 'interleaved' flag to be changed after the fi...
CVE-2022-38784HIGH7.8Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg...
CVE-2022-38625HIGH8.8Patlite NH-FB v1.46 and below was discovered to contain insufficient firmware validation during the upgrade firmware fil...
CVE-2022-37681HIGH7.5Hitachi Kokusai Electric Newtork products for monitoring system (Camera, Decoder and Encoder) and below allows attckers ...
CVE-2022-37680HIGH7.5An improper authentication for critical function issue in Hitachi Kokusai Electric Network products for monitoring syste...
CVE-2022-38772HIGH8.8Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils...
CVE-2022-37177HIGH7.5HireVue Hiring Platform V1.0 suffers from Use of a Broken or Risky Cryptographic Algorithm. NOTE: this is disputed by th...
CVE-2022-36036HIGH7.8mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection ...
CVE-2022-2559HIGH7.2The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters befo...
CVE-2022-2261HIGH7.2The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require...
CVE-2022-1123HIGH7.2The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitiz...
CVE-2022-36034HIGH7.5nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of `{{` and with many repetitions o...
CVE-2022-27558HIGH7.5HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced ...
CVE-2022-27547HIGH7.4HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to tr...
CVE-2022-36200HIGH7.5In FiberHome VDSL2 Modem HG150-Ub_V3.0, Credentials of Admin are submitted in URL, which can be logged/sniffed.
CVE-2022-2961HIGH7A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition...
CVE-2022-1199HIGH7.5A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio...
CVE-2022-1117HIGH8.4A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how glibc names the runtime lin...
CVE-2022-1043HIGH8.8A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows an attacker with a local account to cor...
CVE-2022-0934HIGH7.5A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a cr...
CVE-2022-0850HIGH7.1A vulnerability was found in linux kernel, where an information leak occurs via ext4_extent_header to userspace.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now