2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-33985HIGH7DMA transactions which are targeted at input buffers used for the NvmExpressDxe software SMI handler could cause SMRAM c...
CVE-2022-33984HIGH7DMA transactions which are targeted at input buffers used for the SdMmcDevice software SMI handler could cause SMRAM cor...
CVE-2022-33983HIGH7DMA transactions which are targeted at input buffers used for the NvmExpressLegacy software SMI handler could cause SMRA...
CVE-2022-33909HIGH7DMA transactions which are targeted at input buffers used for the HddPassword software SMI handler could cause SMRAM cor...
CVE-2022-33908HIGH7DMA transactions which are targeted at input buffers used for the SdHostDriver software SMI handler could cause SMRAM co...
CVE-2022-33906MEDIUM6.4DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI handler could cause SMR...
CVE-2022-33905HIGH7DMA transactions which are targeted at input buffers used for the AhciBusDxe software SMI handler could cause SMRAM corr...
CVE-2022-32267MEDIUM6.4DMA transactions which are targeted at input buffers used for the SmmResourceCheckDxe software SMI handler cause SMRAM c...
CVE-2022-31243MEDIUM6.4Update description and links DMA transactions which are targeted at input buffers used for the software SMI handler used...
CVE-2022-30774MEDIUM6.4DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after parameter values have been...
CVE-2022-43695MEDIUM4.8Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting ...
CVE-2022-43691MEDIUM5.3Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 inadvertently disclose server-side sensitive ...
CVE-2022-43690MEDIUM6.3Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 did not use strict comparison for the legacy_...
CVE-2022-43689MEDIUM5.3Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leadi...
CVE-2022-43688MEDIUM4.8Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Stored Cross-Site Scripting ...
CVE-2022-43687MEDIUM5.4Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 does not issue a new session ID upon successf...
CVE-2022-43030HIGH7.2Siyucms v6.1.7 was discovered to contain a remote code execution (RCE) vulnerability in the background. SIYUCMS is a con...
CVE-2022-40903MEDIUM6.5Aiphone GT-DMB-N 3-in-1 Video Entrance Station with NFC Reader 1.0.3 does not mitigate against repeated failed access at...
CVE-2022-40735HIGH7.5The Diffie-Hellman Key Agreement Protocol allows use of long exponents that arguably make certain calculations unnecessa...
CVE-2022-34325HIGH7.8DMA transactions which are targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler could c...
CVE-2022-33982MEDIUM6.4DMA attacks on the parameter buffer used by the Int15ServiceSmm software SMI handler could lead to a TOCTOU attack on th...
CVE-2022-33907MEDIUM6.4DMA transactions which are targeted at input buffers used for the software SMI handler used by the IdeBusDxe driver coul...
CVE-2022-43968MEDIUM6.1Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the dashboa...
CVE-2022-43967MEDIUM6.1Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the multili...
CVE-2022-43686MEDIUM6.5In Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2, the authTypeConcreteCookieMap table can b...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now