2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-20082HIGH7In GPU, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wit...
CVE-2022-28935HIGH7.2Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, T...
CVE-2022-24139HIGH7.8In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with ...
CVE-2022-24138HIGH7.8IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of IOBit suite into ProgramD...
CVE-2022-30591HIGH7.5quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in...
CVE-2022-22681HIGH7.5Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote a...
CVE-2022-31116HIGH7.5UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Affected versions were fou...
CVE-2022-34878HIGH8.8SQL Injection vulnerability in User Stats interface (/vicidial/user_stats.php) of VICIdial via the file_download paramet...
CVE-2022-34877HIGH8.8SQL Injection vulnerability in AST Agent Time Sheet interface ((/vicidial/AST_agent_time_sheet.php) of VICIdial via the ...
CVE-2022-34876HIGH8.8SQL Injection vulnerability in admin interface (/vicidial/admin.php) of VICIdial via modify_email_accounts, access_recor...
CVE-2022-33743HIGH7.8network backend may cause Linux netfront to use freed SKBs While adding logic to support XDP (eXpress Data Path), a code...
CVE-2022-33742HIGH7.1Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspec...
CVE-2022-33741HIGH7.1Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspec...
CVE-2022-33740HIGH7.1Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspec...
CVE-2022-30290HIGH7.5In OpenCTI through 5.2.4, a broken access control vulnerability has been identified in the profile endpoint. An attacker...
CVE-2022-2304HIGH7.8Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
CVE-2022-26365HIGH7.1Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspec...
CVE-2022-2309HIGH7.5NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lx...
CVE-2022-2306HIGH7.5Old session tokens can be used to authenticate to the application and send authenticated requests.
CVE-2022-34918HIGH7.8An issue was discovered in the Linux kernel through 5.18.9. A type confusion bug in nft_set_elem_init (leading to a buff...
CVE-2022-34829HIGH7.5Zoho ManageEngine ADSelfService Plus before 6203 allows a denial of service (application restart) via a crafted payload ...
CVE-2022-31600HIGH8.2NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmmCore, where a user with high privileges can chain another vu...
CVE-2022-31599HIGH8.2NVIDIA DGX A100 contains a vulnerability in SBIOS in the Ofbd, where a local user with elevated privileges can cause acc...
CVE-2022-2268HIGH7.2The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and automatically extracts the zip...
CVE-2022-29484HIGH8.1Operation restriction bypass vulnerability in Space of Cybozu Garoon 4.0.0 to 5.9.0 allows a remote authenticated attack...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now