2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3236 | CRITICAL | 9.8 | 98.9% | Sep 23, 2022 | A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewa... |
| CVE-2022-2347 | HIGH | 7.1 | 0.6% | Sep 23, 2022 | There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DF... |
| CVE-2022-40716 | MEDIUM | 6.5 | 0.8% | Sep 23, 2022 | HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CS... |
| CVE-2022-2566 | HIGH | 7.8 | 0.6% | Sep 23, 2022 | A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points... |
| CVE-2022-40979 | MEDIUM | 5.3 | 0.3% | Sep 23, 2022 | In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perf... |
| CVE-2022-38936 | HIGH | 7.5 | 0.7% | Sep 23, 2022 | An issue has been found in PBC through 2022-8-27. A SEGV issue detected in the function pbc_wmessage_integer in src/wmes... |
| CVE-2022-2785 | MEDIUM | 5.5 | 0.2% | Sep 23, 2022 | There exists an arbitrary memory read within the Linux Kernel BPF - Constants provided to fill pointers in structs passe... |
| CVE-2022-3269 | CRITICAL | 9.8 | 0.7% | Sep 23, 2022 | Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7. |
| CVE-2022-33683 | MEDIUM | 5.9 | 0.6% | Sep 23, 2022 | Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, eve... |
| CVE-2022-33682 | MEDIUM | 5.9 | 0.6% | Sep 23, 2022 | TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, t... |
| CVE-2022-33681 | MEDIUM | 5.9 | 0.6% | Sep 23, 2022 | Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in... |
| CVE-2022-24280 | MEDIUM | 6.5 | 1.2% | Sep 23, 2022 | Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection... |
| CVE-2022-39239 | MEDIUM | 5.4 | 0.3% | Sep 23, 2022 | netlify-ipx is an on-Demand image optimization for Netlify using ipx. In versions prior to 1.2.3, an attacker can bypass... |
| CVE-2022-39238 | HIGH | 8.8 | 0.4% | Sep 23, 2022 | Arvados is an open source platform for managing and analyzing biomedical big data. In versions prior to 2.4.3, when usin... |
| CVE-2022-39231 | LOW | 3.7 | 0.4% | Sep 23, 2022 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio... |
| CVE-2022-26112 | CRITICAL | 9.8 | 1.3% | Sep 23, 2022 | In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in un... |
| CVE-2022-39230 | MEDIUM | 6.5 | 0.6% | Sep 23, 2022 | fhir-works-on-aws-authz-smart is an implementation of the authorization interface from the FHIR Works interface. Version... |
| CVE-2022-39227 | CRITICAL | 9.1 | 3.6% | Sep 23, 2022 | python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authenticati... |
| CVE-2022-39225 | LOW | 3.1 | 0.4% | Sep 23, 2022 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio... |
| CVE-2022-41322 | HIGH | 7.8 | 0.5% | Sep 23, 2022 | In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code e... |
| CVE-2022-41320 | MEDIUM | 6.5 | 0.5% | Sep 23, 2022 | Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during con... |
| CVE-2022-41319 | MEDIUM | 6.1 | 0.4% | Sep 23, 2022 | A Reflected Cross-Site Scripting (XSS) vulnerability affects the Veritas Desktop Laptop Option (DLO) application login p... |
| CVE-2022-35951 | CRITICAL | 9.8 | 2.7% | Sep 23, 2022 | Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Inte... |
| CVE-2022-37235 | CRITICAL | 9.8 | 1.0% | Sep 23, 2022 | Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow... |
| CVE-2022-37232 | CRITICAL | 9.8 | 1.0% | Sep 23, 2022 | Netgear N300 wireless router wnr2000v4-V1.0.0.70 is vulnerable to Buffer Overflow via uhttpd. There is a stack overflow ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now