2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2519 | MEDIUM | 6.5 | 0.9% | Aug 31, 2022 | There is a double free or corruption in rotateImage() at tiffcrop.c:8839 found in libtiff 4.4.0rc1 |
| CVE-2022-2153 | MEDIUM | 5.5 | 0.4% | Aug 31, 2022 | A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbeh... |
| CVE-2022-28625 | MEDIUM | 5.5 | 0.2% | Aug 31, 2022 | A local disclosure of sensitive information vulnerability was discovered in HPE OneView version(s): Prior to 7.0 or 6.60... |
| CVE-2022-26331 | MEDIUM | 6.1 | 0.4% | Aug 31, 2022 | Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exp... |
| CVE-2022-1975 | MEDIUM | 5.5 | 0.2% | Aug 31, 2022 | There is a sleep-in-atomic bug in /net/nfc/netlink.c that allows an attacker to crash the Linux kernel by simulating a n... |
| CVE-2022-1974 | MEDIUM | 4.1 | 0.1% | Aug 31, 2022 | A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject cre... |
| CVE-2022-1508 | MEDIUM | 6.1 | 0.2% | Aug 31, 2022 | An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() func... |
| CVE-2022-1355 | MEDIUM | 6.1 | 0.5% | Aug 31, 2022 | A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a ... |
| CVE-2022-1354 | MEDIUM | 5.5 | 0.5% | Aug 31, 2022 | A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an ... |
| CVE-2022-1325 | MEDIUM | 5.5 | 0.4% | Aug 31, 2022 | A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy heade... |
| CVE-2022-1263 | MEDIUM | 5.5 | 0.4% | Aug 31, 2022 | A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allow... |
| CVE-2022-1205 | MEDIUM | 4.7 | 0.4% | Aug 31, 2022 | A NULL pointer dereference flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a ... |
| CVE-2022-27911 | MEDIUM | 5.3 | 0.5% | Aug 31, 2022 | An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused... |
| CVE-2022-37023 | MEDIUM | 6.5 | 1.3% | Aug 31, 2022 | Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on ... |
| CVE-2022-39046 | MEDIUM | 5.3 | 1.5% | Aug 31, 2022 | An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string lar... |
| CVE-2022-36748 | MEDIUM | 6.1 | 0.4% | Aug 30, 2022 | PicUploader v2.6.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /master/index.... |
| CVE-2022-36747 | MEDIUM | 6.1 | 0.5% | Aug 30, 2022 | Razor v0.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the function uploadchannel(). |
| CVE-2022-36746 | MEDIUM | 6.1 | 0.4% | Aug 30, 2022 | LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component oxidized-cfg-che... |
| CVE-2022-36745 | MEDIUM | 6.1 | 0.4% | Aug 30, 2022 | LibreNMS v22.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component print-customoid.... |
| CVE-2022-27560 | MEDIUM | 6.5 | 0.4% | Aug 30, 2022 | HCL VersionVault Express exposes administrator credentials. |
| CVE-2022-36657 | MEDIUM | 4.8 | 0.5% | Aug 30, 2022 | Library Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /l... |
| CVE-2022-36561 | MEDIUM | 5.5 | 0.3% | Aug 30, 2022 | XPDF v4.0.4 was discovered to contain a segmentation violation via the component /xpdf/AcroForm.cc:538. |
| CVE-2022-34375 | MEDIUM | 6.5 | 1.1% | Aug 30, 2022 | Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote au... |
| CVE-2022-34368 | MEDIUM | 6.5 | 0.3% | Aug 30, 2022 | Dell EMC NetWorker 19.2.1.x 19.3.x, 19.4.x, 19.5.x, 19.6.x and 19.7.0.0 contain an Improper Handling of Insufficient Per... |
| CVE-2022-33935 | MEDIUM | 5.4 | 0.4% | Aug 30, 2022 | Dell EMC Data Protection Advisor versions 19.6 and earlier, contains a Stored Cross Site Scripting, an attacker could po... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now