2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-35030MEDIUM6.5OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fe954.
CVE-2022-35029MEDIUM6.5OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6babea.
CVE-2022-35028MEDIUM6.5OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbbb6.
CVE-2022-35027MEDIUM6.5OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fe9a7.
CVE-2022-35026MEDIUM6.5OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x4fbc0b.
CVE-2022-35025MEDIUM6.5OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x5266a8.
CVE-2022-35024MEDIUM6.5OTFCC commit 617837b was discovered to contain a segmentation violation via /multiarch/memmove-vec-unaligned-erms.S.
CVE-2022-35023MEDIUM6.5OTFCC commit 617837b was discovered to contain a segmentation violation via /lib/x86_64-linux-gnu/libc.so.6+0xbb384.
CVE-2022-35022MEDIUM6.5OTFCC commit 617837b was discovered to contain a segmentation violation via /release-x64/otfccdump+0x6badae.
CVE-2022-35021MEDIUM6.5OTFCC commit 617837b was discovered to contain a global buffer overflow via /release-x64/otfccdump+0x718693.
CVE-2022-40932HIGH7.2In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "galle...
CVE-2022-35408HIGH8.2An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM callout vulnerability in the SMM driver ...
CVE-2022-40146HIGH7.5Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files usin...
CVE-2022-38648MEDIUM5.3Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external re...
CVE-2022-38398MEDIUM5.3Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru t...
CVE-2022-1941HIGH7.5A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3...
CVE-2022-40447HIGH7.2ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the keyword parameter at /admin/baojia_list.php.
CVE-2022-40446HIGH7.2ZZCMS 2022 was discovered to contain a SQL injection vulnerability via the component /admin/sendmailto.php?tomail=&group...
CVE-2022-40444MEDIUM5.3ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server.
CVE-2022-40443MEDIUM5.3An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GE...
CVE-2022-3256HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0530.
CVE-2022-3268CRITICAL9.8Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.
CVE-2022-3267MEDIUM4.3Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.6.
CVE-2022-40705HIGH7.5An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an atta...
CVE-2022-2266MEDIUM6.1University Library Automation System developed by Yordam Bilgi Teknolojileri before version 19.2 has an unauthenticated ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now