2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38791 | MEDIUM | 5.5 | 0.2% | Aug 27, 2022 | In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream w... |
| CVE-2022-2787 | MEDIUM | 4.3 | 0.8% | Aug 27, 2022 | Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot s... |
| CVE-2022-3015 | MEDIUM | 6.1 | 0.3% | Aug 27, 2022 | A vulnerability, which was classified as problematic, has been found in oretnom23 Fast Food Ordering System. This issue ... |
| CVE-2022-3014 | MEDIUM | 6.1 | 0.5% | Aug 27, 2022 | A vulnerability classified as problematic was found in SourceCodester Simple Task Managing System. This vulnerability af... |
| CVE-2022-36548 | MEDIUM | 5.4 | 0.5% | Aug 26, 2022 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /pa... |
| CVE-2022-36547 | MEDIUM | 6.1 | 0.5% | Aug 26, 2022 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at ... |
| CVE-2022-36542 | MEDIUM | 6.5 | 0.6% | Aug 26, 2022 | An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitra... |
| CVE-2022-36522 | MEDIUM | 6.5 | 1.1% | Aug 26, 2022 | Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools... |
| CVE-2022-35714 | MEDIUM | 5.4 | 0.4% | Aug 26, 2022 | IBM Maximo Asset Management 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr... |
| CVE-2022-34303 | MEDIUM | 6.7 | 0.8% | Aug 26, 2022 | A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with... |
| CVE-2022-34302 | MEDIUM | 6.7 | 1.1% | Aug 26, 2022 | A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or ... |
| CVE-2022-34301 | MEDIUM | 6.7 | 0.9% | Aug 26, 2022 | A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass o... |
| CVE-2022-0225 | MEDIUM | 5.4 | 2.6% | Aug 26, 2022 | A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name whil... |
| CVE-2022-0216 | MEDIUM | 4.4 | 0.4% | Aug 26, 2022 | A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs whil... |
| CVE-2022-0207 | MEDIUM | 4.7 | 0.2% | Aug 26, 2022 | A race condition was found in vdsm. Functionality to obfuscate sensitive values in log files that may lead to values bei... |
| CVE-2022-0175 | MEDIUM | 5.5 | 0.3% | Aug 26, 2022 | A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when... |
| CVE-2022-0171 | MEDIUM | 5.5 | 0.3% | Aug 26, 2022 | A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-le... |
| CVE-2022-0168 | MEDIUM | 4.4 | 0.3% | Aug 26, 2022 | A denial of service (DOS) issue was found in the Linux kernel’s smb2_ioctl_query_info function in the fs/cifs/smb2ops.c ... |
| CVE-2022-37150 | MEDIUM | 5.4 | 0.5% | Aug 26, 2022 | An issue was discovered in Online Diagnostic Lab Management System 1.0. There is a stored XSS vulnerability via firstnam... |
| CVE-2022-38533 | MEDIUM | 5.5 | 0.3% | Aug 26, 2022 | In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip... |
| CVE-2022-36121 | MEDIUM | 5.3 | 0.6% | Aug 26, 2022 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue ... |
| CVE-2022-37318 | MEDIUM | 6.1 | 0.4% | Aug 25, 2022 | Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated mal... |
| CVE-2022-37317 | MEDIUM | 5.4 | 0.6% | Aug 25, 2022 | Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could poten... |
| CVE-2022-37316 | MEDIUM | 6.5 | 0.6% | Aug 25, 2022 | Archer Platform 6.8 before 6.11 P3 (6.11.0.3) contains an improper API access control vulnerability in a multi-instance ... |
| CVE-2022-36118 | MEDIUM | 5.3 | 0.6% | Aug 25, 2022 | An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now