2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34394 | LOW | 3.7 | 0.3% | Sep 28, 2022 | Dell OS10, version 10.5.3.4, contains an Improper Certificate Validation vulnerability in Support Assist. A remote unaut... |
| CVE-2022-29089 | MEDIUM | 4.9 | 0.5% | Sep 28, 2022 | Dell Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an information disclos... |
| CVE-2022-3287 | MEDIUM | 6.5 | 0.6% | Sep 28, 2022 | When creating an OPERATOR user account on the BMC, the redfish plugin saved the auto-generated password to /etc/fwupd/re... |
| CVE-2022-3215 | HIGH | 7.5 | 0.5% | Sep 28, 2022 | NIOHTTP1 and projects using it for generating HTTP responses can be subject to a HTTP Response Injection attack. This oc... |
| CVE-2022-39251 | HIGH | 7.5 | 0.9% | Sep 28, 2022 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating w... |
| CVE-2022-39249 | HIGH | 7.5 | 0.9% | Sep 28, 2022 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating w... |
| CVE-2022-39248 | HIGH | 7.5 | 0.7% | Sep 28, 2022 | matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious home... |
| CVE-2022-39246 | MEDIUM | 5.3 | 0.6% | Sep 28, 2022 | matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious home... |
| CVE-2022-36781 | MEDIUM | 5.3 | 0.5% | Sep 28, 2022 | ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom acce... |
| CVE-2022-23716 | MEDIUM | 5.3 | 0.5% | Sep 28, 2022 | A flaw was discovered in ECE before 3.1.1 that could lead to the disclosure of the SAML signing private key used for the... |
| CVE-2022-1270 | HIGH | 7.8 | 0.4% | Sep 28, 2022 | In GraphicsMagick, a heap buffer overflow was found when parsing MIFF. |
| CVE-2022-3193 | MEDIUM | 6.1 | 0.4% | Sep 28, 2022 | An HTML injection/reflected Cross-site scripting (XSS) vulnerability was found in the ovirt-engine. A parameter "error_d... |
| CVE-2022-40929 | CRITICAL | 9.8 | 1.2% | Sep 28, 2022 | XXL-JOB 2.2.0 has a Command execution vulnerability in background tasks. NOTE: this is disputed because the issues/4929 ... |
| CVE-2022-39236 | MEDIUM | 5.3 | 1.0% | Sep 28, 2022 | Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly form... |
| CVE-2022-38934 | LOW | 3.3 | 0.3% | Sep 28, 2022 | readelf in ToaruOS 2.0.1 has some arbitrary address read vulnerabilities when parsing a crafted ELF file. |
| CVE-2022-3354 | HIGH | 7.5 | 0.7% | Sep 28, 2022 | A vulnerability has been found in Open5GS up to 2.4.10 and classified as problematic. This vulnerability affects unknown... |
| CVE-2022-36771 | MEDIUM | 6.5 | 0.5% | Sep 28, 2022 | IBM QRadar User Behavior Analytics could allow an authenticated user to obtain sensitive information from that they shou... |
| CVE-2022-36448 | HIGH | 8.2 | 0.3% | Sep 28, 2022 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. There is an SMM memory corruption vulnerability... |
| CVE-2022-35722 | MEDIUM | 5.4 | 0.4% | Sep 28, 2022 | IBM Jazz for Service Management is vulnerable to stored cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2022-35282 | MEDIUM | 6.5 | 0.3% | Sep 28, 2022 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to server-side request forgery (SSRF). By sending ... |
| CVE-2022-22387 | MEDIUM | 5.4 | 0.4% | Sep 28, 2022 | IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc... |
| CVE-2022-40942 | CRITICAL | 9.8 | 8.1% | Sep 28, 2022 | Tenda TX3 US_TX3V1.0br_V16.03.13.11 is vulnerable to stack overflow via compare_parentcontrol_time. |
| CVE-2022-40912 | MEDIUM | 6.1 | 0.5% | Sep 28, 2022 | ETAP Lighting International NV ETAP Safety Manager 1.0.0.32 is vulnerable to Cross Site Scripting (XSS). Input passed to... |
| CVE-2022-40083 | CRITICAL | 9.6 | 2.3% | Sep 28, 2022 | Labstack Echo v4.8.0 was discovered to contain an open redirect vulnerability via the Static Handler component. This vul... |
| CVE-2022-40082 | HIGH | 7.5 | 0.9% | Sep 28, 2022 | Hertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now