2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-35061MEDIUM6.5OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6e412a.
CVE-2022-35060MEDIUM6.5OTFCC commit 617837b was discovered to contain a heap buffer overflow via /release-x64/otfccdump+0x6c0a32.
CVE-2022-28321CRITICAL9.8The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for SSH logins. The pam_acce...
CVE-2022-0143CRITICAL9.8When the LDAP connector is started with StartTLS configured, unauthenticated access is granted. This issue affects: all ...
CVE-2022-38351HIGH8.8A vulnerability in Suprema BioStar (aka Bio Star) 2 v2.8.16 allows attackers to escalate privileges to System Administra...
CVE-2022-28204HIGH7.5A denial-of-service issue was discovered in MediaWiki 1.37.x before 1.37.2. Rendering of w/index.php?title=Special%3AWha...
CVE-2022-28203HIGH7.5A denial-of-service issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. Whe...
CVE-2022-28201MEDIUM4.4An issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. Users with the editi...
CVE-2022-3239HIGH7.8A flaw use after free in the Linux kernel video4linux driver was found in the way user triggers em28xx_usb_probe() for t...
CVE-2022-38576HIGH7.2Interview Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /interview/de...
CVE-2022-2995HIGH7.1Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclos...
CVE-2022-29835MEDIUM5.3WD Discovery software executable files were signed with an unsafe SHA-1 hashing algorithm. An attacker could use this we...
CVE-2022-23768CRITICAL9.8This Vulnerability in NIS-HAP11AC is caused by an exposed external port for the telnet service. Remote attackers use thi...
CVE-2022-23767CRITICAL9.8This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also i...
CVE-2022-23766HIGH8.8An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order ...
CVE-2022-40980CRITICAL9.1A potential unathenticated file deletion vulnerabilty on Trend Micro Mobile Security for Enterprise 9.8 SP5 could allow ...
CVE-2022-40608HIGH7.5IBM Spectrum Protect Plus 10.1.6 through 10.1.11 Microsoft File Systems restore operation can download any file on the t...
CVE-2022-40234MEDIUM5.9Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a cer...
CVE-2022-40144CRITICAL9.8A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the prod...
CVE-2022-40143HIGH7.3A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service ...
CVE-2022-40142HIGH7.8A security link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a...
CVE-2022-40141HIGH7.5A vulnerability in Trend Micro Apex One and Apex One as a Service could allow an attacker to intercept and decode certai...
CVE-2022-40140MEDIUM5.5An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker ...
CVE-2022-40139HIGH7.2Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One a...
CVE-2022-3213MEDIUM5.5A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lea...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now