2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-40764 | HIGH | 7.8 | 0.5% | Oct 3, 2022 | Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploit... |
| CVE-2022-40721 | CRITICAL | 9.8 | 1.1% | Oct 3, 2022 | Arbitrary file upload vulnerability in php uploader |
| CVE-2022-33890 | HIGH | 7.8 | 0.4% | Oct 3, 2022 | A maliciously crafted PCT or DWF file when consumed through DesignReview.exe application could lead to memory corruption... |
| CVE-2022-33889 | HIGH | 7.8 | 0.2% | Oct 3, 2022 | A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could... |
| CVE-2022-33888 | HIGH | 7.8 | 0.4% | Oct 3, 2022 | A malicious crafted Dwg2Spd file when processed through Autodesk DWG application could lead to memory corruption vulnera... |
| CVE-2022-33887 | HIGH | 7.8 | 0.3% | Oct 3, 2022 | A maliciously crafted PDF file when parsed through Autodesk AutoCAD 2023 causes an unhandled exception. An attacker can ... |
| CVE-2022-33886 | HIGH | 7.8 | 0.3% | Oct 3, 2022 | A maliciously crafted MODEL and SLDPRT file can be used to write beyond the allocated buffer while parsing through Autod... |
| CVE-2022-33885 | HIGH | 7.8 | 0.3% | Oct 3, 2022 | A maliciously crafted X_B, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write b... |
| CVE-2022-33884 | HIGH | 7.5 | 0.7% | Oct 3, 2022 | Parsing a maliciously crafted X_B file can force Autodesk AutoCAD 2023 and 2022 to read beyond allocated boundaries. Thi... |
| CVE-2022-33883 | HIGH | 7.8 | 0.4% | Oct 3, 2022 | A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Materi... |
| CVE-2022-41430 | HIGH | 8.8 | 0.7% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBit function in mp4mux. |
| CVE-2022-41429 | HIGH | 8.8 | 0.7% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_Atom::TypeFromString function in mp4tag. |
| CVE-2022-41428 | HIGH | 8.8 | 0.7% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadBits function in mp4mux. |
| CVE-2022-41427 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a memory leak in the AP4_AvcFrameParser::Feed function in mp4mux. |
| CVE-2022-41426 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_AtomFactory::CreateAtomFromStream function in mp4s... |
| CVE-2022-41425 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_Processor::ProcessFragments function in... |
| CVE-2022-41424 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_SttsAtom::Create function in mp42hls. |
| CVE-2022-41423 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a segmentation violation in the mp4fragment component. |
| CVE-2022-41420 | MEDIUM | 5.5 | 0.3% | Oct 3, 2022 | nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component |
| CVE-2022-41419 | MEDIUM | 6.5 | 0.6% | Oct 3, 2022 | Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt bina... |
| CVE-2022-3132 | MEDIUM | 4.8 | 0.6% | Oct 3, 2022 | The Goolytics WordPress plugin before 1.1.2 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2022-3128 | MEDIUM | 4.8 | 0.5% | Oct 3, 2022 | The Donation Thermometer WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could al... |
| CVE-2022-3125 | HIGH | 8.8 | 1.1% | Oct 3, 2022 | The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to ren... |
| CVE-2022-3124 | MEDIUM | 5.3 | 6.2% | Oct 3, 2022 | The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files f... |
| CVE-2022-2839 | MEDIUM | 5.4 | 0.4% | Oct 3, 2022 | The Zephyr Project Manager WordPress plugin before 3.2.55 does not have any authorisation as well as CSRF in all its AJA... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now