2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24098 | HIGH | 7.8 | 2.4% | May 6, 2022 | Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an improper input validation vulne... |
| CVE-2022-23802 | HIGH | 7.5 | 1.1% | May 6, 2022 | Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). ... |
| CVE-2022-23205 | HIGH | 7.8 | 2.1% | May 6, 2022 | Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerabili... |
| CVE-2022-28165 | HIGH | 8.8 | 1.1% | May 6, 2022 | A vulnerability in the role-based access control (RBAC) functionality of the Brocade SANNav before 2.2.0 could allow an ... |
| CVE-2022-26889 | HIGH | 8.8 | 1.3% | May 6, 2022 | In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to ... |
| CVE-2022-21934 | HIGH | 8.8 | 0.8% | May 6, 2022 | Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts i... |
| CVE-2022-28973 | HIGH | 7.5 | 1.1% | May 6, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the function fromAdvSetMacM... |
| CVE-2022-28972 | HIGH | 7.5 | 1.1% | May 6, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the function form_fast_se... |
| CVE-2022-28971 | HIGH | 7.5 | 1.1% | May 6, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the list parameter in the function fromSetIpMacBind... |
| CVE-2022-28970 | HIGH | 7.5 | 1.1% | May 6, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a heap overflow via the mac parameter in the function GetParentControlIn... |
| CVE-2022-28969 | HIGH | 7.5 | 1.1% | May 6, 2022 | Tenda AX1806 v1.0.0.1 was discovered to contain a stack overflow via the shareSpeed parameter in the function fromSetWif... |
| CVE-2022-30293 | HIGH | 7.5 | 2.0% | May 6, 2022 | In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setC... |
| CVE-2022-24877 | HIGH | 8.8 | 1.1% | May 6, 2022 | Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller v... |
| CVE-2022-29171 | HIGH | 7.2 | 1.2% | May 6, 2022 | Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote ... |
| CVE-2022-29164 | HIGH | 7.1 | 0.8% | May 6, 2022 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. In affe... |
| CVE-2022-24903 | HIGH | 8.1 | 3.6% | May 6, 2022 | Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overfl... |
| CVE-2022-24884 | HIGH | 7.5 | 1.0% | May 6, 2022 | ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` doe... |
| CVE-2022-29173 | HIGH | 8.8 | 0.5% | May 5, 2022 | go-tuf is a Go implementation of The Update Framework (TUF). go-tuf does not correctly implement the client workflow for... |
| CVE-2022-29167 | HIGH | 7.5 | 1.0% | May 5, 2022 | Hawk is an HTTP authentication scheme providing mechanisms for making authenticated HTTP requests with partial cryptogra... |
| CVE-2022-29166 | HIGH | 8.8 | 0.9% | May 5, 2022 | matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate... |
| CVE-2022-29176 | HIGH | 7.5 | 1.7% | May 5, 2022 | Rubygems is a package registry used to supply software for the Ruby language ecosystem. Due to a bug in the yank action,... |
| CVE-2022-25989 | HIGH | 8.8 | 1.0% | May 5, 2022 | An authentication bypass vulnerability exists in the libxm_av.so getpeermac() functionality of Anker Eufy Homebase 2 2.1... |
| CVE-2022-29501 | HIGH | 8.8 | 2.5% | May 5, 2022 | SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execu... |
| CVE-2022-29500 | HIGH | 8.8 | 2.0% | May 5, 2022 | SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure. |
| CVE-2022-29491 | HIGH | 7.5 | 0.9% | May 5, 2022 | On F5 BIG-IP LTM, Advanced WAF, ASM, or APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x v... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now