2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32540 | MEDIUM | 5.9 | 0.3% | Sep 30, 2022 | Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 vers... |
| CVE-2022-28851 | MEDIUM | 5.4 | 36.8% | Sep 30, 2022 | Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabi... |
| CVE-2022-21826 | MEDIUM | 5.4 | 45.2% | Sep 30, 2022 | Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application rece... |
| CVE-2022-1959 | MEDIUM | 6.6 | 0.4% | Sep 30, 2022 | AppLock version 7.9.29 allows an attacker with physical access to the device to bypass biometric authentication. This is... |
| CVE-2022-41440 | HIGH | 7.2 | 0.7% | Sep 30, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventor... |
| CVE-2022-41439 | HIGH | 7.2 | 0.7% | Sep 30, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventor... |
| CVE-2022-41437 | HIGH | 7.2 | 1.3% | Sep 30, 2022 | Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php... |
| CVE-2022-23726 | MEDIUM | 4.9 | 0.6% | Sep 30, 2022 | PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authenticat... |
| CVE-2022-3371 | HIGH | 7.5 | 1.0% | Sep 30, 2022 | Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3. |
| CVE-2022-37461 | MEDIUM | 6.1 | 0.9% | Sep 30, 2022 | Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers... |
| CVE-2022-2529 | HIGH | 7.5 | 0.8% | Sep 30, 2022 | sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attack... |
| CVE-2022-2922 | MEDIUM | 4.9 | 1.0% | Sep 30, 2022 | Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0. |
| CVE-2022-41850 | MEDIUM | 4.7 | 0.2% | Sep 30, 2022 | roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant u... |
| CVE-2022-41849 | MEDIUM | 4.2 | 0.3% | Sep 30, 2022 | drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a... |
| CVE-2022-41848 | MEDIUM | 4.2 | 0.2% | Sep 30, 2022 | drivers/char/pcmcia/synclink_cs.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free ... |
| CVE-2022-41847 | MEDIUM | 5.5 | 0.4% | Sep 30, 2022 | An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*,... |
| CVE-2022-41846 | MEDIUM | 5.5 | 0.3% | Sep 30, 2022 | An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::Reall... |
| CVE-2022-41845 | MEDIUM | 5.5 | 0.3% | Sep 30, 2022 | An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_Array<AP4_ElstEnt... |
| CVE-2022-41844 | MEDIUM | 5.5 | 0.4% | Sep 30, 2022 | An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a differe... |
| CVE-2022-41843 | MEDIUM | 5.5 | 0.3% | Sep 30, 2022 | An issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerabilit... |
| CVE-2022-41842 | MEDIUM | 5.5 | 0.4% | Sep 30, 2022 | An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc. |
| CVE-2022-41841 | MEDIUM | 5.5 | 0.3% | Sep 30, 2022 | An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_File::ParseStream in Core/... |
| CVE-2022-24373 | HIGH | 7.5 | 1.2% | Sep 30, 2022 | The package react-native-reanimated before 3.0.0-rc.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due... |
| CVE-2022-21222 | HIGH | 7.5 | 1.4% | Sep 30, 2022 | The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of ins... |
| CVE-2022-2778 | CRITICAL | 9.8 | 0.7% | Sep 30, 2022 | In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now