2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-40126 | HIGH | 7.8 | 0.3% | Sep 29, 2022 | A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows attackers to escalate privi... |
| CVE-2022-3352 | HIGH | 7.8 | 0.5% | Sep 29, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0614. |
| CVE-2022-3355 | MEDIUM | 5.4 | 0.6% | Sep 29, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository inventree/inventree prior to 0.8.3. |
| CVE-2022-40279 | HIGH | 7.5 | 1.1% | Sep 29, 2022 | An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). l2_packet_receive_timeout in wpa_supplicant/sr... |
| CVE-2022-40278 | HIGH | 7.5 | 1.3% | Sep 29, 2022 | An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisio... |
| CVE-2022-38222 | HIGH | 7.8 | 0.4% | Sep 29, 2022 | There is a use-after-free issue in JBIG2Stream::close() located in JBIG2Stream.cc in Xpdf 4.04. It can be triggered by s... |
| CVE-2022-1725 | MEDIUM | 5.5 | 0.5% | Sep 29, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4959. |
| CVE-2022-1719 | MEDIUM | 5.4 | 0.7% | Sep 29, 2022 | Reflected XSS on ticket filter function in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability is capab... |
| CVE-2022-1718 | HIGH | 7.5 | 1.0% | Sep 29, 2022 | The trudesk application allows large characters to insert in the input field "Full Name" on the signup field which can a... |
| CVE-2022-40048 | HIGH | 7.2 | 2.3% | Sep 29, 2022 | Flatpress v1.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the Upload File function. |
| CVE-2022-39173 | HIGH | 7.5 | 4.3% | Sep 29, 2022 | In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an a... |
| CVE-2022-35888 | MEDIUM | 6.5 | 0.6% | Sep 29, 2022 | Ampere Altra and Ampere Altra Max devices through 2022-07-15 allow attacks via Hertzbleed, which is a power side-channel... |
| CVE-2022-3326 | MEDIUM | 4.3 | 0.5% | Sep 29, 2022 | Weak Password Requirements in GitHub repository ikus060/rdiffweb prior to 2.4.9. |
| CVE-2022-31629 | MEDIUM | 6.5 | 49.3% | Sep 28, 2022 | In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a sta... |
| CVE-2022-31628 | MEDIUM | 5.5 | 0.6% | Sep 28, 2022 | In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip ... |
| CVE-2022-39264 | MEDIUM | 5.9 | 0.6% | Sep 28, 2022 | nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers... |
| CVE-2022-40710 | HIGH | 7.8 | 0.2% | Sep 28, 2022 | A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could... |
| CVE-2022-40709 | LOW | 3.3 | 0.4% | Sep 28, 2022 | An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows ... |
| CVE-2022-40708 | LOW | 3.3 | 0.2% | Sep 28, 2022 | An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows ... |
| CVE-2022-40707 | LOW | 3.3 | 0.2% | Sep 28, 2022 | An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows ... |
| CVE-2022-3292 | MEDIUM | 4.6 | 0.5% | Sep 28, 2022 | Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8. |
| CVE-2022-39263 | HIGH | 8.1 | 0.6% | Sep 28, 2022 | `@next-auth/upstash-redis-adapter` is the Upstash Redis adapter for NextAuth.js, which provides authentication for Next.... |
| CVE-2022-39257 | HIGH | 7.5 | 0.7% | Sep 28, 2022 | Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker coopera... |
| CVE-2022-39255 | HIGH | 7.5 | 0.7% | Sep 28, 2022 | Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker coopera... |
| CVE-2022-34424 | HIGH | 7.5 | 0.6% | Sep 28, 2022 | Networking OS10, versions 10.5.1.x, 10.5.2.x, and 10.5.3.x contain a vulnerability that could allow an attacker to cause... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now