2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-24098HIGH7.8Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an improper input validation vulne...
CVE-2022-23802HIGH7.5Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). ...
CVE-2022-23205HIGH7.8Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerabili...
CVE-2022-28165HIGH8.8A vulnerability in the role-based access control (RBAC) functionality of the Brocade SANNav before 2.2.0 could allow an ...
CVE-2022-26889HIGH8.8In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to ...
CVE-2022-21934HIGH8.8Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts i...
CVE-2022-28973HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the function fromAdvSetMacM...
CVE-2022-28972HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the function form_fast_se...
CVE-2022-28971HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function fromSetIpMacBind...
CVE-2022-28970HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow via the mac parameter in the function GetParentControlIn...
CVE-2022-28969HIGH7.5Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWif...
CVE-2022-30293HIGH7.5In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setC...
CVE-2022-24877HIGH8.8Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller v...
CVE-2022-29171HIGH7.2Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote ...
CVE-2022-29164HIGH7.1Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. In affe...
CVE-2022-24903HIGH8.1Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overfl...
CVE-2022-24884HIGH7.5ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` doe...
CVE-2022-29173HIGH8.8go-tuf is a Go implementation of The Update Framework (TUF). go-tuf does not correctly implement the client workflow for...
CVE-2022-29167HIGH7.5Hawk is an HTTP authentication scheme providing mechanisms for making authenticated HTTP requests with partial cryptogra...
CVE-2022-29166HIGH8.8matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate...
CVE-2022-29176HIGH7.5Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action,...
CVE-2022-25989HIGH8.8An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1...
CVE-2022-29501HIGH8.8SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execu...
CVE-2022-29500HIGH8.8SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.
CVE-2022-29491HIGH7.5On F5 BIG-IP LTM, Advanced WAF, ASM, or APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x v...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now