2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-43243MEDIUM6.5Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_weighted_pred_avg_8_sse i...
CVE-2022-43242MEDIUM6.5Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via mc_luma<unsigned char> in motion.cc. ...
CVE-2022-43241MEDIUM6.5Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_v_3_8_sse in sse-motion.cc. This vu...
CVE-2022-43240MEDIUM6.5Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_qpel_h_2_v_1_sse in ...
CVE-2022-43239MEDIUM6.5Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via mc_chroma<unsigned short> in motion.c...
CVE-2022-43238MEDIUM6.5Libde265 v1.0.8 was discovered to contain an unknown crash via ff_hevc_put_hevc_qpel_h_3_v_3_sse in sse-motion.cc. This ...
CVE-2022-43237MEDIUM6.5Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via void put_epel_hv_fallback<unsigned s...
CVE-2022-43236MEDIUM6.5Libde265 v1.0.8 was discovered to contain a stack-buffer-overflow vulnerability via put_qpel_fallback<unsigned short> in...
CVE-2022-43235MEDIUM6.5Libde265 v1.0.8 was discovered to contain a heap-buffer-overflow vulnerability via ff_hevc_put_hevc_epel_pixels_8_sse in...
CVE-2022-43670MEDIUM5.4An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Sling ...
CVE-2022-40840MEDIUM6.1ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Cross Site Scripting (XSS) via createPdf.php.
CVE-2022-3827CRITICAL9.8A vulnerability was found in centreon. It has been declared as critical. This vulnerability affects unknown code of the ...
CVE-2022-3826MEDIUM6.5A vulnerability was found in Huaxia ERP. It has been classified as problematic. This affects an unknown part of the file...
CVE-2022-3825MEDIUM6.5A vulnerability was found in Huaxia ERP 2.3 and classified as critical. Affected by this issue is some unknown functiona...
CVE-2022-3810MEDIUM6.5A vulnerability was found in Axiomatic Bento4. It has been classified as problematic. This affects the function AP4_File...
CVE-2022-3809MEDIUM6.5A vulnerability was found in Axiomatic Bento4 and classified as problematic. Affected by this issue is the function Pars...
CVE-2022-39379CRITICAL9.8Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ...
CVE-2022-43985MEDIUM6.1In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint.
CVE-2022-43982MEDIUM6.1In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `...
CVE-2022-42473MEDIUM5.5A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 and 7.0.0 - 7.0.3 and...
CVE-2022-39950MEDIUM5.4An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAn...
CVE-2022-39949MEDIUM5.5An improper control of a resource through its lifetime vulnerability [CWE-664] in FortiEDR CollectorWindows 4.0.0 throug...
CVE-2022-39945MEDIUM6.5An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all ve...
CVE-2022-38381CRITICAL9.8An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 5.0 all versions, 6.0.0 all version...
CVE-2022-38380MEDIUM4.3An improper access control [CWE-284] vulnerability in FortiOS version 7.2.0 and versions 7.0.0 through 7.0.7 may allow a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now