2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2251HIGH8Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and...
CVE-2022-23538HIGH7.6github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Ser...
CVE-2022-4891HIGH7.5A vulnerability has been found in Sisimai up to 4.25.14p11 and classified as problematic. This vulnerability affects the...
CVE-2022-37436MEDIUM5.3Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting ...
CVE-2022-36760CRITICAL9Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Se...
CVE-2022-47853CRITICAL9.8TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacke...
CVE-2022-40704MEDIUM6.1A XSS vulnerability was found in phoromatic_r_add_test_details.php in phoronix-test-suite.
CVE-2022-3650HIGH7.8A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root...
CVE-2022-23739CRITICAL9.8An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileg...
CVE-2022-4121MEDIUM5.5In libetpan a null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c was found...
CVE-2022-41861MEDIUM6.5A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which ca...
CVE-2022-41860HIGH7.5In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the...
CVE-2022-41859HIGH7.5In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an atta...
CVE-2022-41858HIGH7.1A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach ...
CVE-2022-4621HIGH8.8Panasonic Sanyo CCTV Network Cameras versions 1.02-05 and 2.03-0x are vulnerable to CSRFs that can be exploited to allo...
CVE-2022-3091HIGH7.5RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials....
CVE-2022-2893MEDIUM6.5RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to s...
CVE-2022-47318HIGH8ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a ...
CVE-2022-46648HIGH8ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a ...
CVE-2022-46891HIGH8.8An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make imp...
CVE-2022-40273Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2022-40272Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2022-40271Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2022-40270Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2022-3117Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now