2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-2872MEDIUM5.4Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.
CVE-2022-40754MEDIUM6.1In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.
CVE-2022-41218MEDIUM5.5In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount rac...
CVE-2022-35090MEDIUM5.5SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_m...
CVE-2022-35089MEDIUM5.5SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/...
CVE-2022-35088MEDIUM5.5SWFTools commit 772e55a2 was discovered to contain a heap buffer-overflow via getGifDelayTime at /home/bupt/Desktop/swft...
CVE-2022-35087MEDIUM5.5SWFTools commit 772e55a2 was discovered to contain a segmentation violation via MovieAddFrame at /src/gif2swf.c.
CVE-2022-35086MEDIUM5.5SWFTools commit 772e55a2 was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.
CVE-2022-35085MEDIUM5.5SWFTools commit 772e55a2 was discovered to contain a memory leak via /lib/mem.c.
CVE-2022-35957MEDIUM6.6Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable t...
CVE-2022-39220MEDIUM6.1SFTPGo is an SFTP server written in Go. Versions prior to 2.3.5 are subject to Cross-site scripting (XSS) vulnerabilitie...
CVE-2022-32883MEDIUM5.5A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS ...
CVE-2022-32880MEDIUM6.5This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.5. An app may be able to...
CVE-2022-32868MEDIUM4.3A logic issue was addressed with improved state management. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadO...
CVE-2022-32864MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 1...
CVE-2022-32861MEDIUM5.3A logic issue was addressed with improved state management. This issue is fixed in Safari 15.6, macOS Monterey 12.5. A u...
CVE-2022-32854MEDIUM5.5This issue was addressed with improved checks. This issue is fixed in iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11...
CVE-2022-32795MEDIUM4.3This issue was addressed with improved checks. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. Visiting a malic...
CVE-2022-33735MEDIUM6.5There is a password verification vulnerability in WS7200-10 11.0.2.13. Attackers on the LAN may use brute force cracking...
CVE-2022-38956MEDIUM5.3An exploitable firmware downgrade vulnerability was discovered on the Netgear WPN824EXT WiFi Range Extender. An attacker...
CVE-2022-32167MEDIUM5.4Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functi...
CVE-2022-3245MEDIUM6.1HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS...
CVE-2022-3242MEDIUM6.1Code Injection in GitHub repository microweber/microweber prior to 1.3.2.
CVE-2022-3005MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.
CVE-2022-3004MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now