2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-40758HIGH7.5A Buffer Access with Incorrect Length Value vulnerablity in the TEE_CipherUpdate function in Samsung mTower through 0.3....
CVE-2022-40757HIGH7.5A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACComputeFinal function in Samsung mTower through 0...
CVE-2022-40755MEDIUM5.5JasPer 3.0.6 allows denial of service via a reachable assertion in the function inttobits in libjasper/base/jas_image.c.
CVE-2022-3217HIGH7.5When logging in to a VBASE runtime project via Web-Remote, the product uses XOR with a static initial key to obfuscate l...
CVE-2022-37709MEDIUM5.3Tesla Model 3 V11.0(2022.4.5.1 6b701552d7a6) Tesla mobile app v4.23 is vulnerable to Authentication Bypass by spoofing. ...
CVE-2022-37258CRITICAL9.8Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the packageName ...
CVE-2022-37251MEDIUM5.4Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
CVE-2022-37247MEDIUM5.4Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
CVE-2022-36026HIGH7.5TensorFlow is an open source platform for machine learning. If `QuantizeAndDequantizeV3` is given a nonscalar `num_bits`...
CVE-2022-36019HIGH7.5TensorFlow is an open source platform for machine learning. If `FakeQuantWithMinMaxVarsPerChannel` is given `min` or `ma...
CVE-2022-36018HIGH7.5TensorFlow is an open source platform for machine learning. If `RaggedTensorToVariant` is given a `rt_nested_splits` lis...
CVE-2022-35990HIGH7.5TensorFlow is an open source platform for machine learning. When `tf.quantization.fake_quant_with_min_max_vars_per_chann...
CVE-2022-35989HIGH7.5TensorFlow is an open source platform for machine learning. When `MaxPool` receives a window size input array `ksize` wi...
CVE-2022-35988HIGH7.5TensorFlow is an open source platform for machine learning. When `tf.linalg.matrix_rank` receives an empty input `a`, th...
CVE-2022-35987HIGH7.5TensorFlow is an open source platform for machine learning. `DenseBincount` assumes its input tensor `weights` to either...
CVE-2022-35986HIGH7.5TensorFlow is an open source platform for machine learning. If `RaggedBincount` is given an empty input tensor `splits`,...
CVE-2022-35985HIGH7.5TensorFlow is an open source platform for machine learning. If `LRNGrad` is given an `output_image` input tensor that is...
CVE-2022-35984HIGH7.5TensorFlow is an open source platform for machine learning. `ParameterizedTruncatedNormal` assumes `shape` is of type `i...
CVE-2022-35983HIGH7.5TensorFlow is an open source platform for machine learning. If `Save` or `SaveSlices` is run over tensors of an unsuppor...
CVE-2022-35982HIGH7.5TensorFlow is an open source platform for machine learning. If `SparseBincount` is given inputs for `indices`, `values`,...
CVE-2022-35981HIGH7.5TensorFlow is an open source platform for machine learning. `FractionalMaxPoolGrad` validates its inputs with `CHECK` fa...
CVE-2022-35979HIGH7.5TensorFlow is an open source platform for machine learning. If `QuantizedRelu` or `QuantizedRelu6` are given nonscalar i...
CVE-2022-35194MEDIUM5.4TestLink v1.9.20 was discovered to contain a stored cross-site scripting (XSS) vulnerability via /lib/inventory/inventor...
CVE-2022-2333HIGH7.8If an attacker manages to trick a valid user into loading a malicious DLL, the attacker may be able to achieve code exec...
CVE-2022-2332HIGH7.8A local unprivileged attacker may escalate to administrator privileges in Honeywell SoftMaster version 4.51, due to inse...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now