2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-42012MEDIUM6.5An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authentic...
CVE-2022-42011MEDIUM6.5An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authentic...
CVE-2022-42010MEDIUM6.5An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authentic...
CVE-2022-42703MEDIUM5.5mm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf anon_vma double reuse.
CVE-2022-3436HIGH7.5A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance System 1.0. Affected by t...
CVE-2022-3435MEDIUM4.3A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the ...
CVE-2022-3434MEDIUM5.4A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been rated as problematic. Affect...
CVE-2022-39281MEDIUM6.5fat_free_crm is a an open source, Ruby on Rails customer relationship management platform (CRM). In versions prior to 0....
CVE-2022-36635HIGH8.8ZKteco ZKBioSecurity V5000 4.1.3 was discovered to contain a SQL injection vulnerability via the component /baseOpLog.do...
CVE-2022-41442MEDIUM6.1PicUploader v2.6.3 was discovered to contain cross-site scripting (XSS) vulnerability via the setStorageParams function ...
CVE-2022-39959HIGH7.8Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini fol...
CVE-2022-41574HIGH7.5An access-control vulnerability in Gradle Enterprise 2022.4 through 2022.3.1 allows remote attackers to prevent backups ...
CVE-2022-3276HIGH8.8Command injection is possible in the puppetlabs-mysql module prior to version 13.0.0. A malicious actor is able to explo...
CVE-2022-3275CRITICAL9.8Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit ...
CVE-2022-39291MEDIUM5.4ZoneMinder is a free, open source Closed-circuit television software application. Affected versions of zoneminder are su...
CVE-2022-39290MEDIUM6.5ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated use...
CVE-2022-39289HIGH7.5ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder AP...
CVE-2022-39285MEDIUM5.4ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a c...
CVE-2022-31681MEDIUM6.5VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process on...
CVE-2022-31680CRITICAL9.1The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicio...
CVE-2022-39287MEDIUM6.5tiny-csrf is a Node.js cross site request forgery (CSRF) protection middleware. In versions prior to 1.1.0 cookies were ...
CVE-2022-36634HIGH8.8An access control issue in ZKTeco ZKBioSecurity V5000 3.0.5_r allows attackers to arbitrarily create admin users via a c...
CVE-2022-32593MEDIUM6.7In vowe, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p...
CVE-2022-32592MEDIUM6.7In cpu dvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation ...
CVE-2022-32591HIGH7.5In ril, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service w...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now