2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-2874MEDIUM5.5NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0224.
CVE-2022-36024MEDIUM6.5py-cord is a an API wrapper for Discord written in Python. Bots creating using py-cord version 2.0.0 are vulnerable to r...
CVE-2022-29550MEDIUM5.5An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud...
CVE-2022-33311MEDIUM4.3Browse restriction bypass vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated ...
CVE-2022-33151MEDIUM6.1Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows remote attackers ...
CVE-2022-32583MEDIUM4.3Operation restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated ...
CVE-2022-32544MEDIUM4.3Operation restriction bypass vulnerability in Project of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated at...
CVE-2022-32453MEDIUM6.5HTTP header injection vulnerability in Cybozu Office 10.0.0 to 10.8.5 may allow a remote attacker to obtain and/or alter...
CVE-2022-32283MEDIUM4.3Browse restriction bypass vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated attac...
CVE-2022-30693MEDIUM5.3Information disclosure vulnerability in the system configuration of Cybozu Office 10.0.0 to 10.8.5 allows a remote attac...
CVE-2022-30604MEDIUM6.1Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker...
CVE-2022-29891MEDIUM4.3Browse restriction bypass vulnerability in Custom Ap of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated att...
CVE-2022-29487MEDIUM6.1Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker to inject an arbitrary scr...
CVE-2022-28715MEDIUM6.1Cross-site scripting vulnerability in the specific parameters of Cybozu Office 10.0.0 to 10.8.5 allows a remote attacker...
CVE-2022-25986MEDIUM4.3Browse restriction bypass vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.5 allows a remote authenticated att...
CVE-2022-35166MEDIUM5.5libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal.
CVE-2022-35165MEDIUM5.5An issue in AP4_SgpdAtom::AP4_SgpdAtom() of Bento4-1.6.0-639 allows attackers to cause a Denial of Service (DoS) via a c...
CVE-2022-35151MEDIUM6.1kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and current...
CVE-2022-2869MEDIUM5.5libtiff's tiffcrop tool has a uint32_t underflow which leads to out of bounds read and write in the extractContigSamples...
CVE-2022-2868MEDIUM5.5libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause...
CVE-2022-2867MEDIUM5.5libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who suppl...
CVE-2022-35148MEDIUM6.5maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parame...
CVE-2022-35133MEDIUM6.1A cross-site scripting (XSS) vulnerability in CherryTree v0.99.30 allows attackers to execute arbitrary web scripts or H...
CVE-2022-2338MEDIUM5.3Softing Secure Integration Server V1.22 is vulnerable to authentication bypass via a machine-in-the-middle attack. The d...
CVE-2022-38392MEDIUM5.3Certain 5400 RPM hard drives, for laptops and other PCs in approximately 2005 and later, allow physically proximate atta...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now