2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-34254HIGH8.8Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp...
CVE-2022-34253HIGH7.2Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an XML In...
CVE-2022-2833HIGH7.5Endless Infinite loop in Blender-thumnailing due to logical bugs.
CVE-2022-2832HIGH7.5A flaw was found in Blender 3.3.0. A null pointer dereference exists in source/blender/gpu/opengl/gl_backend.cc that may...
CVE-2022-2831HIGH7.5A flaw was found in Blender 3.3.0. An interger overflow in source/blender/blendthumb/src/blendthumb_extract.cc may lead ...
CVE-2022-2661HIGH8.8Sequi PortBloque S has an improper authorization vulnerability, which may allow a low-privileged user to perform adminis...
CVE-2022-37393HIGH7.8Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As ...
CVE-2022-38184HIGH7.5There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a rem...
CVE-2022-38362HIGH8.8Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remot...
CVE-2022-36381HIGH7.2OS command injection vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an adm...
CVE-2022-36293HIGH7.2Buffer overflow vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an administ...
CVE-2022-35734HIGH7.5'Hulu / フールー' App for Android from version 3.0.47 to the version prior to 3.1.2 uses a hard-coded API key for an externa...
CVE-2022-35239HIGH8.8The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and ea...
CVE-2022-33939HIGH7.5CENTUM VP / CS 3000 controller FCS (CP31, CP33, CP345, CP401, and CP451) contains an issue in processing communication p...
CVE-2022-38216HIGH7.5An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with mu...
CVE-2022-36312HIGH8.8Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This i...
CVE-2022-36310HIGH8.8Airspan AirVelocity 1500 software prior to version 15.18.00.2511 had NET-SNMP-EXTEND-MIB enabled on its snmpd service, e...
CVE-2022-36309HIGH8.8Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the Act...
CVE-2022-24951HIGH7A race condition exists in Eternal Terminal prior to version 6.2.0 which allows a local attacker to hijack Eternal Termi...
CVE-2022-24950HIGH7.5A race condition exists in Eternal Terminal prior to version 6.2.0 that allows an authenticated attacker to hijack other...
CVE-2022-24949HIGH7.5A privilege escalation to root exists in Eternal Terminal prior to version 6.2.0. This is due to the combination of a ra...
CVE-2022-38359HIGH8.8Cross-site request forgery attacks can be carried out against the Eyes of Network web application, due to an absence of ...
CVE-2022-38357HIGH8.8Improper neutralization of special elements leaves the Eyes of Network Web application vulnerable to an iFrame injection...
CVE-2022-2817HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0213.
CVE-2022-28756HIGH7.8The Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with version 5.7.3 and before 5.11.5 contain...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now