2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3216 | HIGH | 8.8 | 0.5% | Sep 14, 2022 | A vulnerability has been found in Nintendo Game Boy Color and classified as problematic. This vulnerability affects unkn... |
| CVE-2022-36056 | MEDIUM | 5.5 | 0.1% | Sep 14, 2022 | Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions ... |
| CVE-2022-1972 | — | — | — | Sep 14, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2078. Reason: This candidate is a reservation du... |
| CVE-2022-1835 | — | — | — | Sep 14, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2022-36114 | MEDIUM | 6.5 | 0.8% | Sep 14, 2022 | Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of d... |
| CVE-2022-36113 | HIGH | 8.1 | 1.0% | Sep 14, 2022 | Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source c... |
| CVE-2022-36112 | MEDIUM | 5.8 | 0.5% | Sep 14, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro... |
| CVE-2022-35947 | CRITICAL | 9.8 | 0.9% | Sep 14, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro... |
| CVE-2022-35946 | MEDIUM | 6.5 | 0.7% | Sep 14, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro... |
| CVE-2022-35945 | MEDIUM | 6.1 | 0.5% | Sep 14, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro... |
| CVE-2022-31187 | MEDIUM | 5.4 | 0.6% | Sep 14, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro... |
| CVE-2022-31143 | MEDIUM | 5.3 | 0.7% | Sep 14, 2022 | GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro... |
| CVE-2022-2277 | HIGH | 7.5 | 0.7% | Sep 14, 2022 | Improper Input Validation vulnerability exists in the Hitachi Energy MicroSCADA X SYS600's ICCP stack during the ICCP co... |
| CVE-2022-29922 | HIGH | 7.5 | 0.7% | Sep 14, 2022 | Improper Input Validation vulnerability in the handling of a specially crafted IEC 61850 packet with a valid data item b... |
| CVE-2022-29492 | HIGH | 7.5 | 0.6% | Sep 14, 2022 | Improper Input Validation vulnerability in the handling of a malformed IEC 104 TCP packet in the Hitachi Energy MicroSCA... |
| CVE-2022-1778 | MEDIUM | 4.4 | 0.4% | Sep 14, 2022 | Improper Input Validation vulnerability in Hitachi Energy MicroSCADA X SYS600 while reading a specific configuration fil... |
| CVE-2022-0029 | MEDIUM | 5.5 | 0.2% | Sep 14, 2022 | An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local a... |
| CVE-2022-3212 | HIGH | 7.5 | 0.8% | Sep 14, 2022 | <bytes::Bytes as axum_core::extract::FromRequest>::from_request would not, by default, set a limit for the size of the r... |
| CVE-2022-20364 | HIGH | 7.8 | 0.1% | Sep 14, 2022 | In sysmmu_unmap of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local ... |
| CVE-2022-20231 | MEDIUM | 6.7 | 0.1% | Sep 14, 2022 | In smc_intc_request_fiq of arm_gic.c, there is a possible out of bounds write due to improper input validation. This cou... |
| CVE-2022-3202 | HIGH | 7.1 | 0.2% | Sep 14, 2022 | A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This coul... |
| CVE-2022-38796 | MEDIUM | 6.1 | 0.5% | Sep 14, 2022 | A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be... |
| CVE-2022-22520 | MEDIUM | 5.3 | 0.8% | Sep 14, 2022 | A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connec... |
| CVE-2022-37661 | CRITICAL | 9.8 | 36.2% | Sep 14, 2022 | SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature. |
| CVE-2022-40674 | HIGH | 8.1 | 1.7% | Sep 14, 2022 | libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now