2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-50234HIGH7.8In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: defer registered files gc to io_u...
CVE-2022-50238HIGH7.4The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online Microsoft recommended dr...
CVE-2022-39888MEDIUM4.3Improper access control vulnerability in retrieveExternalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows loca...
CVE-2022-38696CRITICAL9.8In BootRom, there's a possible missing payload size check. This could lead to memory buffer overflow without requiring a...
CVE-2022-38695HIGH7.8In BootRom, there's a possible unchecked command index. This could lead to local escalation of privilege with no additio...
CVE-2022-38694HIGH7.8In BootRom, there is a possible unchecked write address. This could lead to local escalation of privilege with no additi...
CVE-2022-38693CRITICAL9.8In FDL1, there is a possible missing payload size check. This could lead to memory buffer overflow without requiring add...
CVE-2022-38692CRITICAL9.8In BootROM, there is a missing size check for RSA keys in Certificate Type 0 validation. This could lead to memory buffe...
CVE-2022-38691HIGH7.8In BootROM, there is a possible missing validation for Certificate Type 0. This could lead to local escalation of privil...
CVE-2022-45133MEDIUM6.5Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 allows unsafe font upload for skins. A parti...
CVE-2022-43110CRITICAL9.8Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to conf...
CVE-2022-31491CRITICAL10Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-2329...
CVE-2022-45134CRITICAL9.8Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 deserializes user input unsafely during skin...
CVE-2022-50233MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix using strlen with hdev->{dev_na...
CVE-2022-50237MEDIUM5.9The ed25519-dalek crate before 2 for Rust allows a double public key signing function oracle attack. The Keypair impleme...
CVE-2022-4979MEDIUM5.1A cross-site scripting (XSS) vulnerability exists in Sitecore Experience Platform (XP) 7.5 - 10.2 and CMS 7.2 - 7.2 Upda...
CVE-2022-4978CRITICAL9.3Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authenticati...
CVE-2022-50232MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: arm64: set UXN on swapper page tables [ This issue...
CVE-2022-50231HIGH7.1In the Linux kernel, the following vulnerability has been resolved: crypto: arm64/poly1305 - fix a read out-of-bound A...
CVE-2022-50230MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: arm64: set UXN on swapper page tables [ This issue...
CVE-2022-50229HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ALSA: bcd2000: Fix a UAF bug on the error path of p...
CVE-2022-50228MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Don't BUG if userspace injects an interru...
CVE-2022-50227MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: x86/xen: Initialize Xen timer only once Add a...
CVE-2022-50226MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Use kzalloc for sev ioctl interfaces ...
CVE-2022-50225MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: riscv:uprobe fix SR_SPIE set/clear handling In ris...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now