2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27804 | CRITICAL | 9.8 | 3.6% | Oct 25, 2022 | An os command injection vulnerability exists in the web interface util_set_abode_code functionality of Abode Systems, In... |
| CVE-2022-27623 | CRITICAL | 9.1 | 0.8% | Oct 25, 2022 | Missing authentication for critical function vulnerability in iSCSI management functionality in Synology DiskStation Man... |
| CVE-2022-27622 | MEDIUM | 4.3 | 0.7% | Oct 25, 2022 | Server-Side Request Forgery (SSRF) vulnerability in Package Center functionality in Synology DiskStation Manager (DSM) b... |
| CVE-2022-43680 | HIGH | 7.5 | 2.2% | Oct 24, 2022 | In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEnti... |
| CVE-2022-43677 | MEDIUM | 5.5 | 0.7% | Oct 24, 2022 | In free5GC 3.2.1, a malformed NGAP message can crash the AMF and NGAP decoders via an index-out-of-range panic in aper.G... |
| CVE-2022-41986 | HIGH | 7.5 | 0.6% | Oct 24, 2022 | Information disclosure vulnerability in Android App 'IIJ SmartKey' versions prior to 2.1.4 allows an attacker to obtain ... |
| CVE-2022-41799 | MEDIUM | 6.5 | 0.8% | Oct 24, 2022 | Improper access control vulnerability in GROWI prior to v5.1.4 (v5 series) and versions prior to v4.5.25 (v4 series) all... |
| CVE-2022-41797 | MEDIUM | 6.5 | 0.9% | Oct 24, 2022 | Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android versions prior to 3.3.5 ... |
| CVE-2022-41796 | HIGH | 7.8 | 0.2% | Oct 24, 2022 | Untrusted search path vulnerability in the installer of Content Transfer (for Windows) Ver.1.3 and prior allows an attac... |
| CVE-2022-40984 | CRITICAL | 9.8 | 0.8% | Oct 24, 2022 | Stack-based buffer overflow in WTViewerE series WTViewerE 761941 from 1.31 to 1.61 and WTViewerEfree from 1.01 to 1.52 a... |
| CVE-2022-40690 | MEDIUM | 5.4 | 0.7% | Oct 24, 2022 | Cross-site scripting vulnerability in BookStack versions prior to v22.09 allows a remote authenticated attacker to injec... |
| CVE-2022-3676 | MEDIUM | 6.5 | 0.6% | Oct 24, 2022 | In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode... |
| CVE-2022-39314 | LOW | 3.7 | 0.4% | Oct 24, 2022 | Kirby is a flat-file CMS. In versions prior to 3.5.8.2, 3.6.6.2, 3.7.5.1, and 3.8.1, Kirby is subject to user enumeratio... |
| CVE-2022-39313 | HIGH | 7.5 | 0.7% | Oct 24, 2022 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior t... |
| CVE-2022-39305 | CRITICAL | 9.8 | 1.1% | Oct 24, 2022 | Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac... |
| CVE-2022-38117 | MEDIUM | 6.1 | 0.3% | Oct 24, 2022 | Juiker app hard-coded its AES key in the source code. A physical attacker, after getting the Android root privilege, can... |
| CVE-2022-36368 | MEDIUM | 4.8 | 0.7% | Oct 24, 2022 | Multiple stored cross-site scripting vulnerabilities in the web user interface of IPFire versions prior to 2.27 allows a... |
| CVE-2022-39272 | MEDIUM | 4.3 | 0.6% | Oct 22, 2022 | Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a De... |
| CVE-2022-39259 | MEDIUM | 5.5 | 0.3% | Oct 21, 2022 | jadx is a set of command line and GUI tools for producing Java source code from Android Dex and Apk files. versions prio... |
| CVE-2022-23462 | HIGH | 7.5 | 0.6% | Oct 21, 2022 | IOWOW is a C utility library and persistent key/value storage engine. Versions 1.4.15 and prior contain a stack buffer o... |
| CVE-2022-3649 | HIGH | 7 | 0.8% | Oct 21, 2022 | A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_ino... |
| CVE-2022-3647 | LOW | 3.3 | 0.6% | Oct 21, 2022 | ** DISPUTED ** A vulnerability, which was classified as problematic, was found in Redis up to 6.2.7/7.0.5. Affected is t... |
| CVE-2022-3646 | MEDIUM | 4.3 | 0.8% | Oct 21, 2022 | A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function ni... |
| CVE-2022-34439 | HIGH | 7.5 | 0.9% | Oct 21, 2022 | Dell PowerScale OneFS, versions 8.2.0.x-9.4.0.x contain allocation of Resources Without Limits or Throttling vulnerabili... |
| CVE-2022-34438 | MEDIUM | 6.7 | 0.2% | Oct 21, 2022 | Dell PowerScale OneFS, versions 8.2.x-9.4.0.x, contain a privilege context switching error. A local authenticated malici... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now