2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-27804CRITICAL9.8An os command injection vulnerability exists in the web interface util_set_abode_code functionality of Abode Systems, In...
CVE-2022-27623CRITICAL9.1Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Man...
CVE-2022-27622MEDIUM4.3Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) b...
CVE-2022-43680HIGH7.5In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEnti...
CVE-2022-43677MEDIUM5.5In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in aper.G...
CVE-2022-41986HIGH7.5Information disclosure vulnerability in Android App 'IIJ SmartKey' versions prior to 2.1.4 allows an attacker to obtain ...
CVE-2022-41799MEDIUM6.5Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) all...
CVE-2022-41797MEDIUM6.5Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 ...
CVE-2022-41796HIGH7.8Untrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attac...
CVE-2022-40984CRITICAL9.8Stack-based buffer overflow in WTViewerE series WTViewerE 761941 from 1.31 to 1.61 and WTViewerEfree from 1.01 to 1.52 a...
CVE-2022-40690MEDIUM5.4Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to injec...
CVE-2022-3676MEDIUM6.5In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode...
CVE-2022-39314LOW3.7Kirby is a flat-file CMS. In versions prior to 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, Kirby is subject to user enumeratio...
CVE-2022-39313HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior t...
CVE-2022-39305CRITICAL9.8Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac...
CVE-2022-38117MEDIUM6.1Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can...
CVE-2022-36368MEDIUM4.8Multiple stored cross-site scripting vulnerabilities in the web user interface of IPFire versions prior to 2.27 allows a...
CVE-2022-39272MEDIUM4.3Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a De...
CVE-2022-39259MEDIUM5.5jadx is a set of command line and GUI tools for producing Java source code from Android Dex and Apk files. versions prio...
CVE-2022-23462HIGH7.5IOWOW is a C utility library and persistent key/value storage engine. Versions 1.4.15 and prior contain a stack buffer o...
CVE-2022-3649HIGH7A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_ino...
CVE-2022-3647LOW3.3** DISPUTED ** A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is t...
CVE-2022-3646MEDIUM4.3A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function ni...
CVE-2022-34439HIGH7.5Dell PowerScale OneFS, versions 8.2.0.x-9.4.0.x contain allocation of Resources Without Limits or Throttling vulnerabili...
CVE-2022-34438MEDIUM6.7Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malici...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now