2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35009 | MEDIUM | 6.5 | 0.7% | Aug 16, 2022 | PNGDec commit 8abf6be was discovered to contain a memory allocation problem via asan_malloc_linux.cpp. |
| CVE-2022-35008 | MEDIUM | 6.5 | 0.7% | Aug 16, 2022 | PNGDec commit 8abf6be was discovered to contain a stack overflow via /linux/main.cpp. |
| CVE-2022-35007 | MEDIUM | 6.5 | 0.7% | Aug 16, 2022 | PNGDec commit 8abf6be was discovered to contain a heap buffer overflow via __interceptor_fwrite.part.57 at sanitizer_com... |
| CVE-2022-35004 | MEDIUM | 5.5 | 0.3% | Aug 16, 2022 | JPEGDEC commit be4843c was discovered to contain a FPE via TIFFSHORT at /src/jpeg.inl. |
| CVE-2022-35002 | MEDIUM | 5.5 | 0.3% | Aug 16, 2022 | JPEGDEC commit be4843c was discovered to contain a segmentation fault via TIFFSHORT at /src/jpeg.inl. |
| CVE-2022-35000 | MEDIUM | 5.5 | 0.3% | Aug 16, 2022 | JPEGDEC commit be4843c was discovered to contain a segmentation fault via fseek at /libio/fseek.c. |
| CVE-2022-34999 | MEDIUM | 5.5 | 0.3% | Aug 16, 2022 | JPEGDEC commit be4843c was discovered to contain a FPE via DecodeJPEG at /src/jpeg.inl. |
| CVE-2022-34259 | MEDIUM | 5.3 | 1.4% | Aug 16, 2022 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp... |
| CVE-2022-34258 | MEDIUM | 4.8 | 68.3% | Aug 16, 2022 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored ... |
| CVE-2022-34257 | MEDIUM | 6.1 | 0.9% | Aug 16, 2022 | Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored ... |
| CVE-2022-2846 | MEDIUM | 4.3 | 2.2% | Aug 16, 2022 | The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place wh... |
| CVE-2022-2844 | MEDIUM | 6.1 | 0.4% | Aug 16, 2022 | A vulnerability classified as problematic has been found in MotoPress Timetable and Event Schedule up to 1.4.06. This af... |
| CVE-2022-2843 | MEDIUM | 6.1 | 0.5% | Aug 16, 2022 | A vulnerability was found in MotoPress Timetable and Event Schedule. It has been rated as problematic. Affected by this ... |
| CVE-2022-38189 | MEDIUM | 5.4 | 0.5% | Aug 16, 2022 | A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker t... |
| CVE-2022-30576 | MEDIUM | 5.4 | 0.4% | Aug 16, 2022 | The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - ... |
| CVE-2022-30575 | MEDIUM | 5.4 | 0.5% | Aug 16, 2022 | The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - ... |
| CVE-2022-38194 | MEDIUM | 5.5 | 0.1% | Aug 16, 2022 | In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user re... |
| CVE-2022-38192 | MEDIUM | 5.4 | 0.5% | Aug 16, 2022 | A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker t... |
| CVE-2022-36530 | MEDIUM | 6.1 | 0.7% | Aug 16, 2022 | An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the i... |
| CVE-2022-29959 | MEDIUM | 5.5 | 0.3% | Aug 16, 2022 | Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave a... |
| CVE-2022-2838 | MEDIUM | 5.3 | 0.5% | Aug 16, 2022 | In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced e... |
| CVE-2022-34156 | MEDIUM | 4.8 | 0.2% | Aug 16, 2022 | 'Hulu / フールー' App for iOS versions prior to 3.0.81 improperly verifies server certificates, which may allow an attacker ... |
| CVE-2022-36311 | MEDIUM | 6.1 | 0.4% | Aug 16, 2022 | Airspan AirVelocity 1500 prior to software version 15.18.00.2511 is vulnerable to injection leading to XSS in the SNMP c... |
| CVE-2022-36307 | MEDIUM | 6.8 | 0.3% | Aug 16, 2022 | The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in Air... |
| CVE-2022-36306 | MEDIUM | 6.5 | 0.8% | Aug 16, 2022 | An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS pri... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now