2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-27470HIGH7.8SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). T...
CVE-2022-24901HIGH7.5Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to byp...
CVE-2022-21743HIGH7.8In ion, there is a possible use after free due to an integer overflow. This could lead to local escalation of privilege ...
CVE-2022-20111HIGH8.4In ion, there is a possible use after free due to incorrect error handling. This could lead to local escalation of privi...
CVE-2022-1548HIGH8.8Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook me...
CVE-2022-28792HIGH7.8DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary...
CVE-2022-28783HIGH7.1Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninst...
CVE-2022-27313HIGH7.5An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleti...
CVE-2022-20110HIGH7In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wit...
CVE-2022-20109HIGH7.8In ion, there is a possible use after free due to improper update of reference count. This could lead to local escalatio...
CVE-2022-20099HIGH7.8In aee daemon, there is a possible out of bounds write due to improper input validation. This could lead to local escala...
CVE-2022-20093HIGH7.8In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could le...
CVE-2022-20088HIGH7.8In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local esc...
CVE-2022-20084HIGH7.8In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This ...
CVE-2022-22368HIGH7.5IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker...
CVE-2022-29001HIGH7.2In SpringBootMovie <=1.2, the uploaded file suffix parameter is not filtered, resulting in arbitrary file upload vulnera...
CVE-2022-28505HIGH7.2Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.
CVE-2022-23400HIGH7.1A stack-based buffer overflow vulnerability exists in the IGXMPXMLParser::parseDelimiter functionality of Accusoft Image...
CVE-2022-1473HIGH7.5The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by...
CVE-2022-1292HIGH7.3The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distrib...
CVE-2022-28590HIGH7.2A Remote Code Execution (RCE) vulnerability exists in Pixelimity 1.0 via admin/admin-ajax.php?action=install_theme.
CVE-2022-0916HIGH8.8An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves appli...
CVE-2022-23063HIGH8.8In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed ...
CVE-2022-1554HIGH7.5Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.
CVE-2022-21949HIGH8.8A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote attackers...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now