2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41794 | CRITICAL | 9.8 | 1.9% | Dec 22, 2022 | A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A ... |
| CVE-2022-41684 | MEDIUM | 5.5 | 0.8% | Dec 22, 2022 | A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file dir... |
| CVE-2022-41649 | CRITICAL | 9.1 | 1.5% | Dec 22, 2022 | A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2.... |
| CVE-2022-41639 | CRITICAL | 9.8 | 1.8% | Dec 22, 2022 | A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branc... |
| CVE-2022-38143 | CRITICAL | 9.8 | 1.4% | Dec 22, 2022 | A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A spe... |
| CVE-2022-36354 | MEDIUM | 5.3 | 0.8% | Dec 22, 2022 | A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.1... |
| CVE-2022-22458 | MEDIUM | 6.5 | 0.8% | Dec 22, 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read b... |
| CVE-2022-22457 | MEDIUM | 4.4 | 0.1% | Dec 22, 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain... |
| CVE-2022-22456 | MEDIUM | 6.1 | 0.3% | Dec 22, 2022 | IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allow... |
| CVE-2022-22184 | HIGH | 7.5 | 0.7% | Dec 22, 2022 | An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos O... |
| CVE-2022-43859 | MEDIUM | 4.3 | 0.6% | Dec 22, 2022 | IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object th... |
| CVE-2022-43858 | MEDIUM | 4.3 | 1.0% | Dec 22, 2022 | IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files the... |
| CVE-2022-43857 | MEDIUM | 4.3 | 1.0% | Dec 22, 2022 | IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are ... |
| CVE-2022-3805 | HIGH | 7.5 | 1.6% | Dec 22, 2022 | The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the... |
| CVE-2022-3794 | MEDIUM | 4.3 | 0.6% | Dec 22, 2022 | The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up ... |
| CVE-2022-46885 | HIGH | 8.8 | 0.5% | Dec 22, 2022 | Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Fire... |
| CVE-2022-46883 | HIGH | 8.8 | 0.6% | Dec 22, 2022 | Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety... |
| CVE-2022-46882 | CRITICAL | 9.8 | 0.9% | Dec 22, 2022 | A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firef... |
| CVE-2022-46881 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploita... |
| CVE-2022-46880 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: ... |
| CVE-2022-46879 | HIGH | 8.8 | 0.6% | Dec 22, 2022 | Mozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Mozilla Fuzzing Team re... |
| CVE-2022-46878 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs p... |
| CVE-2022-46877 | MEDIUM | 4.3 | 0.7% | Dec 22, 2022 | By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user... |
| CVE-2022-46875 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a use... |
| CVE-2022-46874 | HIGH | 8.8 | 0.9% | Dec 22, 2022 | A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious ext... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now