2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-35009MEDIUM6.5PNGDec commit 8abf6be was discovered to contain a memory allocation problem via asan_malloc_linux.cpp.
CVE-2022-35008MEDIUM6.5PNGDec commit 8abf6be was discovered to contain a stack overflow via /linux/main.cpp.
CVE-2022-35007MEDIUM6.5PNGDec commit 8abf6be was discovered to contain a heap buffer overflow via __interceptor_fwrite.part.57 at sanitizer_com...
CVE-2022-35004MEDIUM5.5JPEGDEC commit be4843c was discovered to contain a FPE via TIFFSHORT at /src/jpeg.inl.
CVE-2022-35002MEDIUM5.5JPEGDEC commit be4843c was discovered to contain a segmentation fault via TIFFSHORT at /src/jpeg.inl.
CVE-2022-35000MEDIUM5.5JPEGDEC commit be4843c was discovered to contain a segmentation fault via fseek at /libio/fseek.c.
CVE-2022-34999MEDIUM5.5JPEGDEC commit be4843c was discovered to contain a FPE via DecodeJPEG at /src/jpeg.inl.
CVE-2022-34259MEDIUM5.3Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improp...
CVE-2022-34258MEDIUM4.8Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored ...
CVE-2022-34257MEDIUM6.1Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by a stored ...
CVE-2022-2846MEDIUM4.3The Calendar Event Multi View WordPress plugin before 1.4.07 does not have any authorisation and CSRF checks in place wh...
CVE-2022-2844MEDIUM6.1A vulnerability classified as problematic has been found in MotoPress Timetable and Event Schedule up to 1.4.06. This af...
CVE-2022-2843MEDIUM6.1A vulnerability was found in MotoPress Timetable and Event Schedule. It has been rated as problematic. Affected by this ...
CVE-2022-38189MEDIUM5.4A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker t...
CVE-2022-30576MEDIUM5.4The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - ...
CVE-2022-30575MEDIUM5.4The Web Console component of TIBCO Software Inc.'s TIBCO Data Science - Workbench, TIBCO Statistica, TIBCO Statistica - ...
CVE-2022-38194MEDIUM5.5In Esri Portal for ArcGIS versions 10.8.1, a system property is not properly encrypted. This may lead to a local user re...
CVE-2022-38192MEDIUM5.4A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker t...
CVE-2022-36530MEDIUM6.1An issue was discovered in rageframe2 2.6.37. There is a XSS vulnerability in the user agent related parameters of the i...
CVE-2022-29959MEDIUM5.5Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave a...
CVE-2022-2838MEDIUM5.3In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced e...
CVE-2022-34156MEDIUM4.8'Hulu / フールー' App for iOS versions prior to 3.0.81 improperly verifies server certificates, which may allow an attacker ...
CVE-2022-36311MEDIUM6.1Airspan AirVelocity 1500 prior to software version 15.18.00.2511 is vulnerable to injection leading to XSS in the SNMP c...
CVE-2022-36307MEDIUM6.8The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in Air...
CVE-2022-36306MEDIUM6.5An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS pri...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now