2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-2519MEDIUM6.5There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1
CVE-2022-2153MEDIUM5.5A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbeh...
CVE-2022-28625MEDIUM5.5A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60...
CVE-2022-26331MEDIUM6.1Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exp...
CVE-2022-1975MEDIUM5.5There is a sleep-in-atomic bug in /net/nfc/netlink.c that allows an attacker to crash the Linux kernel by simulating a n...
CVE-2022-1974MEDIUM4.1A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject cre...
CVE-2022-1508MEDIUM6.1An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() func...
CVE-2022-1355MEDIUM6.1A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a ...
CVE-2022-1354MEDIUM5.5A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an ...
CVE-2022-1325MEDIUM5.5A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy heade...
CVE-2022-1263MEDIUM5.5A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allow...
CVE-2022-1205MEDIUM4.7A NULL pointer dereference flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a ...
CVE-2022-27911MEDIUM5.3An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused...
CVE-2022-37023MEDIUM6.5Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on ...
CVE-2022-39046MEDIUM5.3An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string lar...
CVE-2022-36748MEDIUM6.1PicUploader v2.6.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /master/index....
CVE-2022-36747MEDIUM6.1Razor v0.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the function uploadchannel().
CVE-2022-36746MEDIUM6.1LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-che...
CVE-2022-36745MEDIUM6.1LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid....
CVE-2022-27560MEDIUM6.5HCL VersionVault Express exposes administrator credentials.
CVE-2022-36657MEDIUM4.8Library Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /l...
CVE-2022-36561MEDIUM5.5XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538.
CVE-2022-34375MEDIUM6.5Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote au...
CVE-2022-34368MEDIUM6.5Dell EMC NetWorker 19.2.1.x 19.3.x, 19.4.x, 19.5.x, 19.6.x and 19.7.0.0 contain an Improper Handling of Insufficient Per...
CVE-2022-33935MEDIUM5.4Dell EMC Data Protection Advisor versions 19.6 and earlier, contains a Stored Cross Site Scripting, an attacker could po...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now