2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-37246MEDIUM5.4Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput....
CVE-2022-37026CRITICAL9.8In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in...
CVE-2022-2265HIGH7.5The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauth...
CVE-2022-3255MEDIUM4.8If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise t...
CVE-2022-38928HIGH7.8XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
CVE-2022-3068HIGH8.8Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.
CVE-2022-2888MEDIUM4.4If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can...
CVE-2022-3080HIGH7.5By sending specific queries to the resolver, an attacker can cause named to crash.
CVE-2022-38178HIGH7.5By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small me...
CVE-2022-38177HIGH7.5By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small me...
CVE-2022-2906HIGH7.5An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of reso...
CVE-2022-2881HIGH8.2The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the proce...
CVE-2022-2795MEDIUM5.3By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's pe...
CVE-2022-2872MEDIUM5.4Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.
CVE-2022-0495CRITICAL9.4The library automation system product KOHA developed by Parantez Teknoloji before version 19.05.03 has an unauthenticate...
CVE-2022-41222HIGH7mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held duri...
CVE-2022-40754MEDIUM6.1In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint.
CVE-2022-40604HIGH7.5In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extr...
CVE-2022-2315CRITICAL9.4Database Software Accreditation Tracking/Presentation Module product before version 2 has an unauthenticated SQL Injecti...
CVE-2022-41220CRITICAL9.8md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: ...
CVE-2022-41218MEDIUM5.5In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount rac...
CVE-2022-39221HIGH7.5McWebserver mod runs a simple HTTP server alongside the Minecraft server in seperate threads. Path traversal in McWebser...
CVE-2022-38619CRITICAL9.8SmartVista SVFE2 v2.2.22 was discovered to contain a SQL injection vulnerability via the UserForm:j_id90 parameter at /S...
CVE-2022-35090MEDIUM5.5SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via __asan_memcpy at /asan/asan_interceptors_m...
CVE-2022-35089MEDIUM5.5SWFTools commit 772e55a2 was discovered to contain a heap-buffer-overflow via getTransparentColor at /home/bupt/Desktop/...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now