2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-43294CRITICAL9.8Tasmota before commit 066878da4d4762a9b6cb169fdf353e804d735cfd was discovered to contain a stack overflow via the Client...
CVE-2022-32266MEDIUM6.4DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU a...
CVE-2022-30773MEDIUM6.4DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have be...
CVE-2022-43295MEDIUM5.5XPDF v4.04 was discovered to contain a stack overflow via the function FileStream::copy() at xpdf/Stream.cc:795.
CVE-2022-43146HIGH7.2An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers t...
CVE-2022-41913MEDIUM5.4Discourse-calendar is a plugin for the Discourse messaging platform which adds the ability to create a dynamic calendar ...
CVE-2022-3903MEDIUM4.6An incorrect read request flaw was found in the Infrared Transceiver USB driver in the Linux kernel. This issue occurs w...
CVE-2022-3362CRITICAL9.8Insufficient Session Expiration in GitHub repository ikus060/rdiffweb prior to 2.5.0.
CVE-2022-3238HIGH7.8A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneou...
CVE-2022-39385MEDIUM6.5Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a ...
CVE-2022-38167MEDIUM6.1The Nintex Workflow plugin 5.2.2.30 for SharePoint allows XSS.
CVE-2022-37109CRITICAL9.8patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is vulnerable to Incorrect Access...
CVE-2022-28764LOW3.3The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.6 is susceptible to a loc...
CVE-2022-27896HIGH7.5Information Exposure Through Log Files vulnerability discovered in Foundry Code-Workbooks where the endpoint backing tha...
CVE-2022-44390MEDIUM5.4A cross-site scripting (XSS) vulnerability in EyouCMS V1.5.9-UTF8-SP1 allows attackers to execute arbitrary web scripts ...
CVE-2022-44389MEDIUM6.5EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit Admin Profile module....
CVE-2022-44387HIGH8.8EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Basic Information componen...
CVE-2022-43323HIGH8.8EyouCMS V1.5.9-UTF8-SP1 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Top Up Balance component u...
CVE-2022-34320HIGH7.5 IBM CICS TX 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sens...
CVE-2022-34317MEDIUM5.4 IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c...
CVE-2022-43694MEDIUM6.1Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS in the image m...
CVE-2022-43692MEDIUM6.1Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to Reflected XSS - user can cau...
CVE-2022-34316MEDIUM5.3 IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP headers that can be used b...
CVE-2022-34315MEDIUM5.4 IBM CICS TX 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript c...
CVE-2022-34314LOW3.3 IBM CICS TX 11.1 could disclose sensitive information to a local user due to insecure permission settings. IBM X-Force ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now