2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38860 | MEDIUM | 5.5 | 0.3% | Sep 15, 2022 | Certain The MPlayer Project products are vulnerable to Divide By Zero via function demux_open_avi() of libmpdemux/demux_... |
| CVE-2022-38858 | MEDIUM | 5.5 | 0.3% | Sep 15, 2022 | Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demu... |
| CVE-2022-38856 | MEDIUM | 5.5 | 0.3% | Sep 15, 2022 | Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demu... |
| CVE-2022-38855 | MEDIUM | 5.5 | 0.3% | Sep 15, 2022 | Certain The MPlayer Project products are vulnerable to Buffer Overflow via function gen_sh_video () of mplayer/libmpdemu... |
| CVE-2022-38853 | MEDIUM | 5.5 | 0.3% | Sep 15, 2022 | Certain The MPlayer Project products are vulnerable to Buffer Overflow via function asf_init_audio_stream() of libmpdemu... |
| CVE-2022-29649 | MEDIUM | 6.1 | 0.4% | Sep 15, 2022 | Qsmart Next v4.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability. |
| CVE-2022-3211 | MEDIUM | 5.4 | 0.4% | Sep 15, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.5.6. |
| CVE-2022-2472 | MEDIUM | 5.5 | 0.3% | Sep 15, 2022 | Improper Initialization vulnerability in the local server component of EZVIZ CS-C6N-A0-1C2WFR allows a local attacker to... |
| CVE-2022-3224 | MEDIUM | 6.1 | 0.6% | Sep 15, 2022 | Misinterpretation of Input in GitHub repository ionicabizau/parse-url prior to 8.1.0. |
| CVE-2022-38788 | MEDIUM | 4.3 | 0.5% | Sep 15, 2022 | An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pa... |
| CVE-2022-3222 | MEDIUM | 5.5 | 0.6% | Sep 15, 2022 | Uncontrolled Recursion in GitHub repository gpac/gpac prior to 2.1.0-DEV. |
| CVE-2022-31735 | MEDIUM | 6.1 | 0.4% | Sep 15, 2022 | OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601)... |
| CVE-2022-40738 | MEDIUM | 6.5 | 0.6% | Sep 15, 2022 | An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_DescriptorListWriter::Acti... |
| CVE-2022-40737 | MEDIUM | 6.5 | 0.6% | Sep 15, 2022 | An issue was discovered in Bento4 through 1.6.0-639. A buffer over-read exists in the function AP4_StdcFileByteStream::W... |
| CVE-2022-40736 | MEDIUM | 6.5 | 0.6% | Sep 15, 2022 | An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in AP4_CttsAtom::Create in Core/Ap4Ct... |
| CVE-2022-40734 | MEDIUM | 6.5 | 4.1% | Sep 14, 2022 | UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversa... |
| CVE-2022-40476 | MEDIUM | 5.5 | 0.3% | Sep 14, 2022 | A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could ... |
| CVE-2022-40439 | MEDIUM | 6.5 | 0.6% | Sep 14, 2022 | An memory leak issue was discovered in AP4_StdcFileByteStream::Create in mp42ts in Bento4 v1.6.0-639, allows attackers t... |
| CVE-2022-40438 | MEDIUM | 6.5 | 0.6% | Sep 14, 2022 | Buffer overflow vulnerability in function AP4_MemoryByteStream::WritePartial in mp42aac in Bento4 v1.6.0-639, allows att... |
| CVE-2022-40365 | MEDIUM | 6.1 | 0.5% | Sep 14, 2022 | Cross site scripting (XSS) vulnerability in ouqiang gocron through 1.5.3, allows attackers to execute arbitrary code via... |
| CVE-2022-37724 | MEDIUM | 6.1 | 0.5% | Sep 14, 2022 | Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XS... |
| CVE-2022-36056 | MEDIUM | 5.5 | 0.1% | Sep 14, 2022 | Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions ... |
| CVE-2022-36114 | MEDIUM | 6.5 | 0.8% | Sep 14, 2022 | Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of d... |
| CVE-2022-36112 | MEDIUM | 5.8 | 0.5% | Sep 14, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro... |
| CVE-2022-35946 | MEDIUM | 6.5 | 0.7% | Sep 14, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now