2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27470 | HIGH | 7.8 | 0.9% | May 4, 2022 | SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). T... |
| CVE-2022-24901 | HIGH | 7.5 | 0.6% | May 4, 2022 | Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to byp... |
| CVE-2022-21743 | HIGH | 7.8 | 0.1% | May 3, 2022 | In ion, there is a possible use after free due to an integer overflow. This could lead to local escalation of privilege ... |
| CVE-2022-20111 | HIGH | 8.4 | 0.1% | May 3, 2022 | In ion, there is a possible use after free due to incorrect error handling. This could lead to local escalation of privi... |
| CVE-2022-1548 | HIGH | 8.8 | 0.5% | May 3, 2022 | Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook me... |
| CVE-2022-28792 | HIGH | 7.8 | 0.2% | May 3, 2022 | DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary... |
| CVE-2022-28783 | HIGH | 7.1 | 0.1% | May 3, 2022 | Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninst... |
| CVE-2022-27313 | HIGH | 7.5 | 0.9% | May 3, 2022 | An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleti... |
| CVE-2022-20110 | HIGH | 7 | 0.1% | May 3, 2022 | In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wit... |
| CVE-2022-20109 | HIGH | 7.8 | 0.1% | May 3, 2022 | In ion, there is a possible use after free due to improper update of reference count. This could lead to local escalatio... |
| CVE-2022-20099 | HIGH | 7.8 | 0.1% | May 3, 2022 | In aee daemon, there is a possible out of bounds write due to improper input validation. This could lead to local escala... |
| CVE-2022-20093 | HIGH | 7.8 | 0.1% | May 3, 2022 | In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could le... |
| CVE-2022-20088 | HIGH | 7.8 | 0.1% | May 3, 2022 | In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local esc... |
| CVE-2022-20084 | HIGH | 7.8 | 0.1% | May 3, 2022 | In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This ... |
| CVE-2022-22368 | HIGH | 7.5 | 0.7% | May 3, 2022 | IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker... |
| CVE-2022-29001 | HIGH | 7.2 | 1.0% | May 3, 2022 | In SpringBootMovie <=1.2, the uploaded file suffix parameter is not filtered, resulting in arbitrary file upload vulnera... |
| CVE-2022-28505 | HIGH | 7.2 | 0.9% | May 3, 2022 | Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java. |
| CVE-2022-23400 | HIGH | 7.1 | 0.8% | May 3, 2022 | A stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft Image... |
| CVE-2022-1473 | HIGH | 7.5 | 2.2% | May 3, 2022 | The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by... |
| CVE-2022-1292 | HIGH | 7.3 | 83.6% | May 3, 2022 | The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distrib... |
| CVE-2022-28590 | HIGH | 7.2 | 22.8% | May 3, 2022 | A Remote Code Execution (RCE) vulnerability exists in Pixelimity 1.0 via admin/admin-ajax.php?action=install_theme. |
| CVE-2022-0916 | HIGH | 8.8 | 0.4% | May 3, 2022 | An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves appli... |
| CVE-2022-23063 | HIGH | 8.8 | 1.2% | May 3, 2022 | In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed ... |
| CVE-2022-1554 | HIGH | 7.5 | 1.3% | May 3, 2022 | Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52. |
| CVE-2022-21949 | HIGH | 8.8 | 1.7% | May 3, 2022 | A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote attackers... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now