2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-40764HIGH7.8Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploit...
CVE-2022-40721CRITICAL9.8Arbitrary file upload vulnerability in php uploader
CVE-2022-33890HIGH7.8A maliciously crafted PCT or DWF file when consumed through DesignReview.exe application could lead to memory corruption...
CVE-2022-33889HIGH7.8A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could...
CVE-2022-33888HIGH7.8A malicious crafted Dwg2Spd file when processed through Autodesk DWG application could lead to memory corruption vulnera...
CVE-2022-33887HIGH7.8A maliciously crafted PDF file when parsed through Autodesk AutoCAD 2023 causes an unhandled exception. An attacker can ...
CVE-2022-33886HIGH7.8A maliciously crafted MODEL and SLDPRT file can be used to write beyond the allocated buffer while parsing through Autod...
CVE-2022-33885HIGH7.8A maliciously crafted X_B, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write b...
CVE-2022-33884HIGH7.5Parsing a maliciously crafted X_B file can force Autodesk AutoCAD 2023 and 2022 to read beyond allocated boundaries. Thi...
CVE-2022-33883HIGH7.8A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Materi...
CVE-2022-41430HIGH8.8Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux.
CVE-2022-41429HIGH8.8Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_Atom::TypeFromString function in mp4tag.
CVE-2022-41428HIGH8.8Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBits function in mp4mux.
CVE-2022-41427MEDIUM6.5Bento4 v1.6.0-639 was discovered to contain a memory leak in the AP4_AvcFrameParser::Feed function in mp4mux.
CVE-2022-41426MEDIUM6.5Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_AtomFactory::CreateAtomFromStream function in mp4s...
CVE-2022-41425MEDIUM6.5Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in...
CVE-2022-41424MEDIUM6.5Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_SttsAtom::Create function in mp42hls.
CVE-2022-41423MEDIUM6.5Bento4 v1.6.0-639 was discovered to contain a segmentation violation in the mp4fragment component.
CVE-2022-41420MEDIUM5.5nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component
CVE-2022-41419MEDIUM6.5Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt bina...
CVE-2022-3132MEDIUM4.8The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2022-3128MEDIUM4.8The Donation Thermometer WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could al...
CVE-2022-3125HIGH8.8The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to ren...
CVE-2022-3124MEDIUM5.3The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files f...
CVE-2022-2839MEDIUM5.4The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJA...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now