2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2471CRITICAL9.8Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component as used in camera models CS-CV248, CS-...
CVE-2022-37266CRITICAL9.8Prototype pollution vulnerability in function extend in babel.js in stealjs steal 2.2.4 via the key variable in babel.js...
CVE-2022-37257CRITICAL9.8Prototype pollution vulnerability in function convertLater in npm-convert.js in stealjs steal 2.2.4 via the requestedVer...
CVE-2022-3224MEDIUM6.1Misinterpretation of Input in GitHub repository ionicabizau/parse-url prior to 8.1.0.
CVE-2022-38789CRITICAL9.1An issue was discovered in Airties Smart Wi-Fi before 2020-08-04. It allows attackers to change the main/guest SSID and ...
CVE-2022-38788MEDIUM4.3An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pa...
CVE-2022-3222MEDIUM5.5Uncontrolled Recursion in GitHub repository gpac/gpac prior to 2.1.0-DEV.
CVE-2022-3221HIGH8.8Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3.
CVE-2022-31735MEDIUM6.1OpenAM Consortium Edition version 14.0.0 provided by OpenAM Consortium contains an open redirect vulnerability (CWE-601)...
CVE-2022-40738MEDIUM6.5An issue was discovered in Bento4 through 1.6.0-639. A NULL pointer dereference occurs in AP4_DescriptorListWriter::Acti...
CVE-2022-40737MEDIUM6.5An issue was discovered in Bento4 through 1.6.0-639. A buffer over-read exists in the function AP4_StdcFileByteStream::W...
CVE-2022-40736MEDIUM6.5An issue was discovered in Bento4 1.6.0-639. There ie excessive memory consumption in AP4_CttsAtom::Create in Core/Ap4Ct...
CVE-2022-38595HIGH7.2Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edi...
CVE-2022-38594HIGH7.2Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edi...
CVE-2022-38352CRITICAL9.8ThinkPHP v6.0.13 was discovered to contain a deserialization vulnerability via the component League\Flysystem\Cached\Sto...
CVE-2022-38323HIGH7.2Event Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /Royal_E...
CVE-2022-40734MEDIUM6.5UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversa...
CVE-2022-40476MEDIUM5.5A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could ...
CVE-2022-40439MEDIUM6.5An memory leak issue was discovered in AP4_StdcFileByteStream::Create in mp42ts in Bento4 v1.6.0-639, allows attackers t...
CVE-2022-40438MEDIUM6.5Buffer overflow vulnerability in function AP4_MemoryByteStream::WritePartial in mp42aac in Bento4 v1.6.0-639, allows att...
CVE-2022-40365MEDIUM6.1Cross site scripting (XSS) vulnerability in ouqiang gocron through 1.5.3, allows attackers to execute arbitrary code via...
CVE-2022-38308CRITICAL9.8TOTOLink A700RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the lang parameter...
CVE-2022-38301HIGH8.8Onedev v7.4.14 contains a path traversal vulnerability which allows attackers to access restricted files and directories...
CVE-2022-37724MEDIUM6.1Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XS...
CVE-2022-2977HIGH7.8A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TP...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now