2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20056 | MEDIUM | 6.6 | 0.1% | Mar 10, 2022 | In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca... |
| CVE-2022-20055 | MEDIUM | 6.8 | 0.1% | Mar 10, 2022 | In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca... |
| CVE-2022-20051 | MEDIUM | 5.5 | 0.1% | Mar 10, 2022 | In ims service, there is a possible unexpected application behavior due to incorrect privilege assignment. This could le... |
| CVE-2022-20050 | MEDIUM | 6.7 | 0.1% | Mar 10, 2022 | In connsyslogger, there is a possible symbolic link following due to improper link resolution. This could lead to local ... |
| CVE-2022-20049 | MEDIUM | 6.7 | 0.1% | Mar 10, 2022 | In vpu, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalati... |
| CVE-2022-0904 | MEDIUM | 6.5 | 0.9% | Mar 10, 2022 | A stack overflow bug in the document extractor in Mattermost Server in versions up to and including 6.3.2 allows an atta... |
| CVE-2022-0865 | MEDIUM | 6.5 | 1.5% | Mar 10, 2022 | Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. Fo... |
| CVE-2022-0856 | MEDIUM | 6.5 | 2.8% | Mar 10, 2022 | libcaca is affected by a Divide By Zero issue via img2txt, which allows a remote malicious user to cause a Denial of Ser... |
| CVE-2022-0433 | MEDIUM | 5.5 | 0.3% | Mar 10, 2022 | A NULL pointer dereference flaw was found in the Linux kernel's BPF subsystem in the way a user triggers the map_get_nex... |
| CVE-2022-0906 | MEDIUM | 4.8 | 0.6% | Mar 10, 2022 | Unrestricted file upload leads to stored XSS in GitHub repository microweber/microweber prior to 1.1.12. |
| CVE-2022-0890 | MEDIUM | 5.5 | 0.8% | Mar 10, 2022 | NULL Pointer Dereference in GitHub repository mruby/mruby prior to 3.2. |
| CVE-2022-24747 | MEDIUM | 5.3 | 1.1% | Mar 9, 2022 | Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. Affected vers... |
| CVE-2022-24746 | MEDIUM | 6.1 | 0.8% | Mar 9, 2022 | Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected v... |
| CVE-2022-24745 | MEDIUM | 6.5 | 0.5% | Mar 9, 2022 | Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework. In affected v... |
| CVE-2022-24323 | MEDIUM | 5.9 | 0.8% | Mar 9, 2022 | A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause a disruption of co... |
| CVE-2022-24322 | MEDIUM | 5.9 | 0.6% | Mar 9, 2022 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause... |
| CVE-2022-24741 | MEDIUM | 6.5 | 1.6% | Mar 9, 2022 | Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can caus... |
| CVE-2022-24919 | MEDIUM | 4.4 | 0.8% | Mar 9, 2022 | An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other u... |
| CVE-2022-24918 | MEDIUM | 4.4 | 0.7% | Mar 9, 2022 | An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other us... |
| CVE-2022-24917 | MEDIUM | 4.4 | 0.8% | Mar 9, 2022 | An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other... |
| CVE-2022-24349 | MEDIUM | 4.4 | 0.8% | Mar 9, 2022 | An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malic... |
| CVE-2022-22511 | MEDIUM | 5.4 | 0.6% | Mar 9, 2022 | Various configuration pages of the device are vulnerable to reflected XSS (Cross-Site Scripting) attacks. An authorized ... |
| CVE-2022-0022 | MEDIUM | 4.4 | 0.1% | Mar 9, 2022 | Usage of a weak cryptographic algorithm in Palo Alto Networks PAN-OS software where the password hashes of administrator... |
| CVE-2022-24526 | MEDIUM | 6.1 | 1.6% | Mar 9, 2022 | Visual Studio Code Spoofing Vulnerability |
| CVE-2022-24522 | MEDIUM | 6.5 | 2.1% | Mar 9, 2022 | Skype Extension for Chrome Information Disclosure Vulnerability |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now