2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-42315MEDIUM6.5Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text exp...
CVE-2022-42314MEDIUM6.5Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text exp...
CVE-2022-42313MEDIUM6.5Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text exp...
CVE-2022-42312MEDIUM6.5Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text exp...
CVE-2022-42311MEDIUM6.5Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text exp...
CVE-2022-42310MEDIUM5.5Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an erro...
CVE-2022-42309HIGH8.8Xenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a malicious guest can cause xenstored to use a w...
CVE-2022-42252HIGH7.5If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to igno...
CVE-2022-3369MEDIUM5.5An Improper Access Control vulnerability in the bdservicehost.exe component, as used in Bitdefender Engines for Windows,...
CVE-2022-25892HIGH7.5The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial...
CVE-2022-25885HIGH7.5The package muhammara before 2.6.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when PDFStr...
CVE-2022-41553MEDIUM5.5Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linu...
CVE-2022-41552CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Data Center Analy...
CVE-2022-3373HIGH8.8Out of bounds write in V8 in Google Chrome prior to 106.0.5249.91 allowed a remote attacker to perform an out of bounds ...
CVE-2022-3370HIGH8.8Use after free in Custom Elements in Google Chrome prior to 106.0.5249.91 allowed a remote attacker to potentially explo...
CVE-2022-3191MEDIUM5.5Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Analyzer on Linux (Virtual Strage S...
CVE-2022-2572CRITICAL9.8In affected versions of Octopus Server where access is managed by an external authentication provider, it was possible t...
CVE-2022-44542CRITICAL9.8lesspipe before 2.06 allows attackers to execute code via Perl Storable (pst) files, because of deserialized object dest...
CVE-2022-43355HIGH7.2Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php...
CVE-2022-43354HIGH7.2Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /adm...
CVE-2022-43353HIGH7.2Sanitization Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /adm...
CVE-2022-43752HIGH7.8Oracle Solaris version 10 1/13, when using the Common Desktop Environment (CDE), is vulnerable to a privilege escalation...
CVE-2022-40296CRITICAL9.8 The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with u...
CVE-2022-40295MEDIUM4.9The application was vulnerable to an authenticated information disclosure, allowing administrators to view unsalted user...
CVE-2022-40294HIGH8.8 The application was identified to have an CSV injection in data export functionality, allowing for malicious code to be...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now