2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-27781HIGH7.5libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's c...
CVE-2022-27780HIGH7.5The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, ma...
CVE-2022-27778HIGH8.1A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used...
CVE-2022-27775HIGH7.5An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address tha...
CVE-2022-27184HIGH7.8The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.
CVE-2022-26975HIGH7.5Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files wit...
CVE-2022-24701HIGH7.8An issue was discovered in WinAPRS 2.9.0. A buffer overflow in national.txt processing allows a local attacker to cause ...
CVE-2022-24700HIGH7.5An issue was discovered in WinAPRS 2.9.0. A buffer overflow in DIGI address processing for VHF KISS packets allows a rem...
CVE-2022-24581HIGH7.5ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an exte...
CVE-2022-24241HIGH7.5ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the t...
CVE-2022-22767HIGH8.8Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentia...
CVE-2022-1968HIGH7.8Use After Free in GitHub repository vim/vim prior to 8.2.
CVE-2022-1949HIGH7.5An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect r...
CVE-2022-1943HIGH7.8A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers s...
CVE-2022-1929HIGH7.5An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacke...
CVE-2022-1797HIGH8.6A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition ...
CVE-2022-1786HIGH7.8A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SE...
CVE-2022-1661HIGH7.5The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating s...
CVE-2022-1652HIGH7.8Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-fre...
CVE-2022-1419HIGH7.8The root cause of this vulnerability is that the ioctl$DRM_IOCTL_MODE_DESTROY_DUMB can decrease refcount of *drm_vgem_ge...
CVE-2022-1215HIGH7.8A format string vulnerability was found in libinput
CVE-2022-29169HIGH7.5BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5....
CVE-2022-30190HIGH7.8A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such ...
CVE-2022-30128HIGH8.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-30127HIGH8.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now