2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28780 | MEDIUM | 5.5 | 0.1% | May 3, 2022 | Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access locati... |
| CVE-2022-27330 | MEDIUM | 5.4 | 0.5% | May 3, 2022 | A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_product of E-Commerce Website v1.0 allows atta... |
| CVE-2022-20100 | MEDIUM | 4.4 | 0.1% | May 3, 2022 | In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local in... |
| CVE-2022-20098 | MEDIUM | 4.4 | 0.1% | May 3, 2022 | In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local in... |
| CVE-2022-20097 | MEDIUM | 4.7 | 0.1% | May 3, 2022 | In aee daemon, there is a possible information disclosure due to a race condition. This could lead to local information ... |
| CVE-2022-20096 | MEDIUM | 4.4 | 0.1% | May 3, 2022 | In camera, there is a possible information disclosure due to uninitialized data. This could lead to local information di... |
| CVE-2022-20095 | MEDIUM | 6.7 | 0.1% | May 3, 2022 | In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation... |
| CVE-2022-20094 | MEDIUM | 6.7 | 0.1% | May 3, 2022 | In imgsensor, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalat... |
| CVE-2022-20092 | MEDIUM | 5.5 | 0.1% | May 3, 2022 | In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local informat... |
| CVE-2022-20091 | MEDIUM | 6.4 | 0.1% | May 3, 2022 | In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privil... |
| CVE-2022-20090 | MEDIUM | 6.4 | 0.1% | May 3, 2022 | In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privil... |
| CVE-2022-20089 | MEDIUM | 6.7 | 0.1% | May 3, 2022 | In aee driver, there is a possible memory corruption due to active debug code. This could lead to local escalation of pr... |
| CVE-2022-20087 | MEDIUM | 6.7 | 0.1% | May 3, 2022 | In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr... |
| CVE-2022-20085 | MEDIUM | 6.7 | 0.1% | May 3, 2022 | In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local esc... |
| CVE-2022-1331 | MEDIUM | 5.5 | 0.7% | May 3, 2022 | In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entitie... |
| CVE-2022-28599 | MEDIUM | 5.4 | 0.5% | May 3, 2022 | A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a... |
| CVE-2022-28588 | MEDIUM | 5.4 | 0.5% | May 3, 2022 | In SpringBootMovie <=1.2 when adding movie names, malicious code can be stored because there are no filtering parameters... |
| CVE-2022-22137 | MEDIUM | 6.5 | 1.1% | May 3, 2022 | A memory corruption vulnerability exists in the ioca_mys_rgb_allocate functionality of Accusoft ImageGear 19.10. A speci... |
| CVE-2022-1434 | MEDIUM | 5.9 | 1.0% | May 3, 2022 | The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the M... |
| CVE-2022-1343 | MEDIUM | 5.3 | 1.1% | May 3, 2022 | The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default... |
| CVE-2022-0882 | MEDIUM | 5.5 | 0.1% | May 3, 2022 | A bug exists where an attacker can read the kernel log through exposed Zircon kernel addresses without the required capa... |
| CVE-2022-28589 | MEDIUM | 4.8 | 0.5% | May 3, 2022 | A stored cross-site scripting (XSS) vulnerability in Pixelimity 1.0 allows attackers to execute arbitrary web scripts or... |
| CVE-2022-20748 | MEDIUM | 5.3 | 1.2% | May 3, 2022 | A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Software could allow an un... |
| CVE-2022-20744 | MEDIUM | 6.5 | 0.9% | May 3, 2022 | A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an au... |
| CVE-2022-20740 | MEDIUM | 6.1 | 0.7% | May 3, 2022 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now