2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-40126HIGH7.8A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privi...
CVE-2022-3352HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0614.
CVE-2022-3355MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3.
CVE-2022-40279HIGH7.5An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). l2_packet_receive_timeout in wpa_supplicant/sr...
CVE-2022-40278HIGH7.5An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisio...
CVE-2022-38222HIGH7.8There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by s...
CVE-2022-1725MEDIUM5.5NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4959.
CVE-2022-1719MEDIUM5.4Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capab...
CVE-2022-1718HIGH7.5The trudesk application allows large characters to insert in the input field "Full Name" on the signup field which can a...
CVE-2022-40048HIGH7.2Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function.
CVE-2022-39173HIGH7.5In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an a...
CVE-2022-35888MEDIUM6.5Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel...
CVE-2022-3326MEDIUM4.3Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9.
CVE-2022-31629MEDIUM6.5In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a sta...
CVE-2022-31628MEDIUM5.5In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip ...
CVE-2022-39264MEDIUM5.9nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers...
CVE-2022-40710HIGH7.8A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could...
CVE-2022-40709LOW3.3An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows ...
CVE-2022-40708LOW3.3An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows ...
CVE-2022-40707LOW3.3An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows ...
CVE-2022-3292MEDIUM4.6Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8.
CVE-2022-39263HIGH8.1`@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next....
CVE-2022-39257HIGH7.5Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker coopera...
CVE-2022-39255HIGH7.5Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker coopera...
CVE-2022-34424HIGH7.5Networking OS10, versions 10.5.1.x, 10.5.2.x, and 10.5.3.x contain a vulnerability that could allow an attacker to cause...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now