2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-32540MEDIUM5.9Information Disclosure in Operator Client application in BVMS 10.1.1, 11.0 and 11.1.0 and VIDEOJET Decoder VJD-7513 vers...
CVE-2022-28851MEDIUM5.4Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabi...
CVE-2022-21826MEDIUM5.4Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application rece...
CVE-2022-1959MEDIUM6.6AppLock version 7.9.29 allows an attacker with physical access to the device to bypass biometric authentication. This is...
CVE-2022-41440HIGH7.2Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventor...
CVE-2022-41439HIGH7.2Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventor...
CVE-2022-41437HIGH7.2Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php...
CVE-2022-23726MEDIUM4.9PingCentral versions prior to listed versions expose Spring Boot actuator endpoints that with administrative authenticat...
CVE-2022-3371HIGH7.5Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.
CVE-2022-37461MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Canon Medical Vitrea View 7.x before 7.7.6 allow remote attackers...
CVE-2022-2529HIGH7.5sflow decode package does not employ sufficient packet sanitisation which can lead to a denial of service attack. Attack...
CVE-2022-2922MEDIUM4.9Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.
CVE-2022-41850MEDIUM4.7roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant u...
CVE-2022-41849MEDIUM4.2drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a...
CVE-2022-41848MEDIUM4.2drivers/char/pcmcia/synclink_cs.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free ...
CVE-2022-41847MEDIUM5.5An issue was discovered in Bento4 1.6.0-639. A memory leak exists in AP4_StdcFileByteStream::Create(AP4_FileByteStream*,...
CVE-2022-41846MEDIUM5.5An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_DataBuffer::Reall...
CVE-2022-41845MEDIUM5.5An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in the function AP4_Array<AP4_ElstEnt...
CVE-2022-41844MEDIUM5.5An issue was discovered in Xpdf 4.04. There is a crash in XRef::fetch(int, int, Object*, int) in xpdf/XRef.cc, a differe...
CVE-2022-41843MEDIUM5.5An issue was discovered in Xpdf 4.04. There is a crash in convertToType0 in fofi/FoFiType1C.cc, a different vulnerabilit...
CVE-2022-41842MEDIUM5.5An issue was discovered in Xpdf 4.04. There is a crash in gfseek(_IO_FILE*, long, int) in goo/gfile.cc.
CVE-2022-41841MEDIUM5.5An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_File::ParseStream in Core/...
CVE-2022-24373HIGH7.5The package react-native-reanimated before 3.0.0-rc.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due...
CVE-2022-21222HIGH7.5The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of ins...
CVE-2022-2778CRITICAL9.8In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now