2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-41794CRITICAL9.8A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A ...
CVE-2022-41684MEDIUM5.5A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file dir...
CVE-2022-41649CRITICAL9.1A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2....
CVE-2022-41639CRITICAL9.8A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branc...
CVE-2022-38143CRITICAL9.8A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A spe...
CVE-2022-36354MEDIUM5.3A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.1...
CVE-2022-22458MEDIUM6.5 IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read b...
CVE-2022-22457MEDIUM4.4IBM Security Verify Governance, Identity Manager 10.0.1 stores sensitive information including user credentials in plain...
CVE-2022-22456MEDIUM6.1 IBM Security Verify Governance, Identity Manager 10.0.1 is vulnerable to cross-site scripting. This vulnerability allow...
CVE-2022-22184HIGH7.5An Improper Input Validation vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos O...
CVE-2022-43859MEDIUM4.3IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object th...
CVE-2022-43858MEDIUM4.3IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files the...
CVE-2022-43857MEDIUM4.3IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are ...
CVE-2022-3805HIGH7.5The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the...
CVE-2022-3794MEDIUM4.3The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various AJAX actions in versions up ...
CVE-2022-46885HIGH8.8Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Fire...
CVE-2022-46883HIGH8.8Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety...
CVE-2022-46882CRITICAL9.8A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firef...
CVE-2022-46881HIGH8.8An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploita...
CVE-2022-46880MEDIUM6.5A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: ...
CVE-2022-46879HIGH8.8Mozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Mozilla Fuzzing Team re...
CVE-2022-46878HIGH8.8Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs p...
CVE-2022-46877MEDIUM4.3By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user...
CVE-2022-46875MEDIUM6.5The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a use...
CVE-2022-46874HIGH8.8A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious ext...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now