2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-28780MEDIUM5.5Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access locati...
CVE-2022-27330MEDIUM5.4A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_product of E-Commerce Website v1.0 allows atta...
CVE-2022-20100MEDIUM4.4In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local in...
CVE-2022-20098MEDIUM4.4In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local in...
CVE-2022-20097MEDIUM4.7In aee daemon, there is a possible information disclosure due to a race condition. This could lead to local information ...
CVE-2022-20096MEDIUM4.4In camera, there is a possible information disclosure due to uninitialized data. This could lead to local information di...
CVE-2022-20095MEDIUM6.7In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation...
CVE-2022-20094MEDIUM6.7In imgsensor, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalat...
CVE-2022-20092MEDIUM5.5In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local informat...
CVE-2022-20091MEDIUM6.4In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privil...
CVE-2022-20090MEDIUM6.4In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privil...
CVE-2022-20089MEDIUM6.7In aee driver, there is a possible memory corruption due to active debug code. This could lead to local escalation of pr...
CVE-2022-20087MEDIUM6.7In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...
CVE-2022-20085MEDIUM6.7In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local esc...
CVE-2022-1331MEDIUM5.5In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entitie...
CVE-2022-28599MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a...
CVE-2022-28588MEDIUM5.4In SpringBootMovie <=1.2 when adding movie names, malicious code can be stored because there are no filtering parameters...
CVE-2022-22137MEDIUM6.5A memory corruption vulnerability exists in the ioca_mys_rgb_allocate functionality of Accusoft ImageGear 19.10. A speci...
CVE-2022-1434MEDIUM5.9The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the M...
CVE-2022-1343MEDIUM5.3The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default...
CVE-2022-0882MEDIUM5.5A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capa...
CVE-2022-28589MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in Pixelimity 1.0 allows attackers to execute arbitrary web scripts or...
CVE-2022-20748MEDIUM5.3A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Software could allow an un...
CVE-2022-20744MEDIUM6.5A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an au...
CVE-2022-20740MEDIUM6.1A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now