2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2872 | MEDIUM | 5.4 | 0.5% | Sep 21, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3. |
| CVE-2022-40754 | MEDIUM | 6.1 | 1.4% | Sep 21, 2022 | In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint. |
| CVE-2022-41218 | MEDIUM | 5.5 | 0.8% | Sep 21, 2022 | In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount rac... |
| CVE-2022-35090 | MEDIUM | 5.5 | 0.3% | Sep 21, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_m... |
| CVE-2022-35089 | MEDIUM | 5.5 | 0.3% | Sep 21, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/... |
| CVE-2022-35088 | MEDIUM | 5.5 | 0.3% | Sep 21, 2022 | SWFTools commit 772e55a2 was discovered to contain a heap buffer-overflow via getGifDelayTime at /home/bupt/Desktop/swft... |
| CVE-2022-35087 | MEDIUM | 5.5 | 0.3% | Sep 21, 2022 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via MovieAddFrame at /src/gif2swf.c. |
| CVE-2022-35086 | MEDIUM | 5.5 | 0.3% | Sep 21, 2022 | SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S. |
| CVE-2022-35085 | MEDIUM | 5.5 | 0.3% | Sep 21, 2022 | SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c. |
| CVE-2022-35957 | MEDIUM | 6.6 | 1.3% | Sep 20, 2022 | Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable t... |
| CVE-2022-39220 | MEDIUM | 6.1 | 0.5% | Sep 20, 2022 | SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilitie... |
| CVE-2022-32883 | MEDIUM | 5.5 | 0.5% | Sep 20, 2022 | A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS ... |
| CVE-2022-32880 | MEDIUM | 6.5 | 0.5% | Sep 20, 2022 | This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.5. An app may be able to... |
| CVE-2022-32868 | MEDIUM | 4.3 | 0.8% | Sep 20, 2022 | A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadO... |
| CVE-2022-32864 | MEDIUM | 5.5 | 0.3% | Sep 20, 2022 | The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 1... |
| CVE-2022-32861 | MEDIUM | 5.3 | 0.5% | Sep 20, 2022 | A logic issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. A u... |
| CVE-2022-32854 | MEDIUM | 5.5 | 0.3% | Sep 20, 2022 | This issue was addressed with improved checks. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11... |
| CVE-2022-32795 | MEDIUM | 4.3 | 0.6% | Sep 20, 2022 | This issue was addressed with improved checks. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. Visiting a malic... |
| CVE-2022-33735 | MEDIUM | 6.5 | 0.2% | Sep 20, 2022 | There is a password verification vulnerability in WS7200-10 11.0.2.13. Attackers on the LAN may use brute force cracking... |
| CVE-2022-38956 | MEDIUM | 5.3 | 0.2% | Sep 20, 2022 | An exploitable firmware downgrade vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker... |
| CVE-2022-32167 | MEDIUM | 5.4 | 0.4% | Sep 20, 2022 | Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functi... |
| CVE-2022-3245 | MEDIUM | 6.1 | 0.5% | Sep 20, 2022 | HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS... |
| CVE-2022-3242 | MEDIUM | 6.1 | 1.4% | Sep 20, 2022 | Code Injection in GitHub repository microweber/microweber prior to 1.3.2. |
| CVE-2022-3005 | MEDIUM | 5.4 | 0.5% | Sep 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. |
| CVE-2022-3004 | MEDIUM | 5.4 | 0.5% | Sep 20, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now