2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3236CRITICAL9.8A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewa...
CVE-2022-2347HIGH7.1There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DF...
CVE-2022-40716MEDIUM6.5HashiCorp Consul and Consul Enterprise up to 1.11.8, 1.12.4, and 1.13.1 do not check for multiple SAN URI values in a CS...
CVE-2022-2566HIGH7.8A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points...
CVE-2022-40979MEDIUM5.3In JetBrains TeamCity before 2022.04.4 environmental variables of "password" type could be logged when using custom Perf...
CVE-2022-38936HIGH7.5An issue has been found in PBC through 2022-8-27. A SEGV issue detected in the function pbc_wmessage_integer in src/wmes...
CVE-2022-2785MEDIUM5.5There exists an arbitrary memory read within the Linux Kernel BPF - Constants provided to fill pointers in structs passe...
CVE-2022-3269CRITICAL9.8Session Fixation in GitHub repository ikus060/rdiffweb prior to 2.4.7.
CVE-2022-33683MEDIUM5.9Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, eve...
CVE-2022-33682MEDIUM5.9TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, t...
CVE-2022-33681MEDIUM5.9Delayed TLS hostname verification in the Pulsar Java Client and the Pulsar Proxy make each client vulnerable to a man in...
CVE-2022-24280MEDIUM6.5Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection...
CVE-2022-39239MEDIUM5.4netlify-ipx is an on-Demand image optimization for Netlify using ipx. In versions prior to 1.2.3, an attacker can bypass...
CVE-2022-39238HIGH8.8Arvados is an open source platform for managing and analyzing biomedical big data. In versions prior to 2.4.3, when usin...
CVE-2022-39231LOW3.7Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio...
CVE-2022-26112CRITICAL9.8In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in un...
CVE-2022-39230MEDIUM6.5fhir-works-on-aws-authz-smart is an implementation of the authorization interface from the FHIR Works interface. Version...
CVE-2022-39227CRITICAL9.1python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authenticati...
CVE-2022-39225LOW3.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prio...
CVE-2022-41322HIGH7.8In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code e...
CVE-2022-41320MEDIUM6.5Veritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during con...
CVE-2022-41319MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability affects the Veritas Desktop Laptop Option (DLO) application login p...
CVE-2022-35951CRITICAL9.8Redis is an in-memory database that persists on disk. Versions 7.0.0 and above, prior to 7.0.5 are vulnerable to an Inte...
CVE-2022-37235CRITICAL9.8Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow...
CVE-2022-37232CRITICAL9.8Netgear N300 wireless router wnr2000v4-V1.0.0.70 is vulnerable to Buffer Overflow via uhttpd. There is a stack overflow ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now