2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-31674MEDIUM4.3VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with netwo...
CVE-2022-2719MEDIUM5.5In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/oper...
CVE-2022-23238MEDIUM6.5Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux ...
CVE-2022-22983MEDIUM5.9VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious acto...
CVE-2022-20357MEDIUM5.5In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could...
CVE-2022-20355MEDIUM5.5In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could le...
CVE-2022-20353MEDIUM5.5In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input v...
CVE-2022-20352MEDIUM5.5In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request lo...
CVE-2022-20350MEDIUM5.5In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notific...
CVE-2022-20346MEDIUM6.5In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds read due to an incor...
CVE-2022-1962MEDIUM5.5Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a ...
CVE-2022-1705MEDIUM6.5Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 al...
CVE-2022-34365MEDIUM6.5WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability,...
CVE-2022-33931MEDIUM5.3Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An attacker with no ...
CVE-2022-33929MEDIUM6.1Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in EndUserSummary pag...
CVE-2022-33927MEDIUM6.5Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could e...
CVE-2022-33926MEDIUM6.5Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user co...
CVE-2022-33925MEDIUM6.5Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authentica...
CVE-2022-33924MEDIUM5.3Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability with which an attacker with...
CVE-2022-29090MEDIUM6.5Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious ...
CVE-2022-22490MEDIUM4.9IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot cr...
CVE-2022-22411MEDIUM6.5IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow...
CVE-2022-20713MEDIUM6.1A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco F...
CVE-2022-38133MEDIUM5.3In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
CVE-2022-2756MEDIUM6.5Server-Side Request Forgery (SSRF) in GitHub repository kareadita/kavita prior to 0.5.4.1.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now