2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-40298HIGH8.8Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation ...
CVE-2022-38573CRITICAL9.810-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.
CVE-2022-30426HIGH7.8There is a stack buffer overflow vulnerability, which could lead to arbitrary code execution in UEFI DXE driver on some ...
CVE-2022-40089CRITICAL9.8A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code vi...
CVE-2022-40088MEDIUM6.1Simple College Website v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the compo...
CVE-2022-40087CRITICAL9.8Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_co...
CVE-2022-36934CRITICAL9.8An integer overflow in WhatsApp could result in remote code execution in an established video call.
CVE-2022-31937CRITICAL9.8Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd.
CVE-2022-23458MEDIUM6.1Toast UI Grid is a component to display and edit data. Versions prior to 4.21.3 are vulnerable to cross-site scripting a...
CVE-2022-37234HIGH7.8Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow...
CVE-2022-3274LOW3.5Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.7.
CVE-2022-36062LOW3.8Grafana is an open-source platform for monitoring and observability. In versions prior to 8.5.13, 9.0.9, and 9.1.6, Graf...
CVE-2022-35894MEDIUM6An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The SMI handler for the FwBlockServiceSmm drive...
CVE-2022-34026HIGH7.5ICEcoder v8.1 allows attackers to execute a directory traversal.
CVE-2022-40935HIGH7.2Online Pet Shop We App v1.0 is vulnerable to SQL Injection via /pet_shop/classes/Master.php?f=delete_category,id.
CVE-2022-40934HIGH7.2Online Pet Shop We App v1.0 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_sub_category,id
CVE-2022-40933HIGH7.2Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,...
CVE-2022-35039MEDIUM6.5OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e20a0.
CVE-2022-35038MEDIUM6.5OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b064d.
CVE-2022-35037MEDIUM6.5OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6adb1e.
CVE-2022-35036MEDIUM6.5OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e1fc8.
CVE-2022-35035MEDIUM6.5OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6b559f.
CVE-2022-35034MEDIUM6.5OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e7e3d.
CVE-2022-35032MEDIUM6.5OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6b6a8f.
CVE-2022-35031MEDIUM6.5OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x703969.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now