2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-1662MEDIUM5.5In convert2rhel, there's an ansible playbook named ansible/run-convert2rhel.yml which passes the Red Hat Subscription Ma...
CVE-2022-2396MEDIUM5.4A vulnerability classified as problematic was found in SourceCodester Simple e-Learning System 1.0. Affected by this vul...
CVE-2022-25803MEDIUM6.1Best Practical Request Tracker (RT) before 5.0.3 has an Open Redirect via a ticket search.
CVE-2022-25802MEDIUM6.1Best Practical Request Tracker (RT) before 4.4.6 and 5.x before 5.0.3 allows XSS via a crafted content type for an attac...
CVE-2022-34765MEDIUM5.3A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware i...
CVE-2022-34758MEDIUM4.9A CWE-20: Improper Input Validation vulnerability exists that could cause the device watchdog function to be disabled if...
CVE-2022-34757MEDIUM5.3A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists where weak cipher suites can be used fo...
CVE-2022-34754MEDIUM6.8A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing cred...
CVE-2022-31145MEDIUM6.5FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. In ve...
CVE-2022-32308MEDIUM6.1Cross Site Scripting (XSS) vulnerability in uBlock Origin extension before 1.41.1 allows remote attackers to run arbitra...
CVE-2022-2380MEDIUM5.5The Linux kernel was found vulnerable out of bounds memory access in the drivers/video/fbdev/sm712fb.c:smtcfb_read() fun...
CVE-2022-20230MEDIUM5.5In choosePrivateKeyAlias of KeyChain.java, there is a possible access to the user's certificate due to improper input va...
CVE-2022-20228MEDIUM6.5In various functions of C2DmaBufAllocator.cpp, there is a possible memory corruption due to a use after free. This could...
CVE-2022-20227MEDIUM5.5In USB driver, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informatio...
CVE-2022-20225MEDIUM5.5In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a m...
CVE-2022-20221MEDIUM6.5In avrc_ctrl_pars_vendor_cmd of avrc_pars_ct.cc, there is a possible out of bounds read due to improper input validation...
CVE-2022-20219MEDIUM5.5In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's...
CVE-2022-20217MEDIUM6.5There is a unauthorized broadcast in the SprdContactsProvider. A third-party app could use this issue to delete Fdn cont...
CVE-2022-34358MEDIUM5.4IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J...
CVE-2022-32074MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-F...
CVE-2022-32065MEDIUM5.4An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to...
CVE-2022-32274MEDIUM5.4The Transition Scheduler add-on 6.5.0 for Atlassian Jira is prone to stored XSS via the project name to the creation fun...
CVE-2022-33673MEDIUM6.5Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-33672MEDIUM6.5Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-33671MEDIUM4.9Azure Site Recovery Elevation of Privilege Vulnerability

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now