2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25719CRITICAL9.1Information disclosure in WLAN due to improper length check while processing authentication handshake in Snapdragon Auto...
CVE-2022-25718CRITICAL9.8Cryptographic issue in WLAN due to improper check on return value while authentication handshake in Snapdragon Auto, Sna...
CVE-2022-25687CRITICAL9.8memory corruption in video due to buffer overflow while parsing asf clips in Snapdragon Auto, Snapdragon Compute, Snapdr...
CVE-2022-25666MEDIUM6.7Memory corruption due to use after free in service while trying to access maps by different threads in Snapdragon Auto, ...
CVE-2022-25665HIGH7.1Information disclosure due to buffer over read in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT...
CVE-2022-25664MEDIUM5.5Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, S...
CVE-2022-25663MEDIUM5.5Possible buffer overflow due to lack of buffer length check during management frame Rx handling lead to denial of servic...
CVE-2022-25662HIGH7.5Information disclosure due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon...
CVE-2022-25661HIGH7.8Memory corruption due to untrusted pointer dereference in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Cons...
CVE-2022-25660HIGH7.8Memory corruption due to double free issue in kernel in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Sn...
CVE-2022-22078MEDIUM4.6Denial of service in BOOT when partition size for a particular partition is requested due to integer overflow when block...
CVE-2022-22077HIGH7.8Memory corruption in graphics due to use-after-free in graphics dispatcher logic in Snapdragon Mobile
CVE-2022-3606MEDIUM5.5A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by...
CVE-2022-42467MEDIUM5.3When running in prototype mode, the h2 webconsole module (accessible from the Prototype menu) is automatically made avai...
CVE-2022-42466MEDIUM6.1Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to...
CVE-2022-40798HIGH7.5OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending t...
CVE-2022-38901MEDIUM5.4A Cross-site scripting (XSS) vulnerability in the Document and Media module - file upload functionality in Liferay Digit...
CVE-2022-35860MEDIUM6.8Missing AES encryption in Corsair K63 Wireless 3.1.3 allows physically proximate attackers to inject and sniff keystroke...
CVE-2022-33077HIGH7.5An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any customer's address via the add...
CVE-2022-41500HIGH8.8EyouCMS V1.5.9 was discovered to contain multiple Cross-Site Request Forgery (CSRF) vulnerabilities via the Members Cent...
CVE-2022-42218HIGH7.2Open Source SACCO Management System v1.0 vulnerable to SQL Injection via /sacco_shield/manage_loan.php.
CVE-2022-42117MEDIUM6.1A Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.3.2 through 7.4.3.16, and L...
CVE-2022-42116MEDIUM6.1A Cross-site scripting (XSS) vulnerability in the Frontend Editor module's integration with CKEditor in Liferay Portal 7...
CVE-2022-42115MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Object module's edit object details page in Liferay Portal 7.4.3.4 throu...
CVE-2022-42114MEDIUM5.4A Cross-site scripting (XSS) vulnerability in the Role module's edit role assignees page in Liferay Portal 7.4.0 through...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now