2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3216HIGH8.8A vulnerability has been found in Nintendo Game Boy Color and classified as problematic. This vulnerability affects unkn...
CVE-2022-36056MEDIUM5.5Cosign is a project under the sigstore organization which aims to make signatures invisible infrastructure. In versions ...
CVE-2022-1972Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-2078. Reason: This candidate is a reservation du...
CVE-2022-1835Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2022-36114MEDIUM6.5Cargo is a package manager for the rust programming language. It was discovered that Cargo did not limit the amount of d...
CVE-2022-36113HIGH8.1Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source c...
CVE-2022-36112MEDIUM5.8GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro...
CVE-2022-35947CRITICAL9.8GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro...
CVE-2022-35946MEDIUM6.5GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro...
CVE-2022-35945MEDIUM6.1GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro...
CVE-2022-31187MEDIUM5.4GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro...
CVE-2022-31143MEDIUM5.3GLPI stands for Gestionnaire Libre de Parc Informatique and is a Free Asset and IT Management Software package, that pro...
CVE-2022-2277HIGH7.5Improper Input Validation vulnerability exists in the Hitachi Energy MicroSCADA X SYS600's ICCP stack during the ICCP co...
CVE-2022-29922HIGH7.5Improper Input Validation vulnerability in the handling of a specially crafted IEC 61850 packet with a valid data item b...
CVE-2022-29492HIGH7.5Improper Input Validation vulnerability in the handling of a malformed IEC 104 TCP packet in the Hitachi Energy MicroSCA...
CVE-2022-1778MEDIUM4.4Improper Input Validation vulnerability in Hitachi Energy MicroSCADA X SYS600 while reading a specific configuration fil...
CVE-2022-0029MEDIUM5.5An improper link resolution vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local a...
CVE-2022-3212HIGH7.5<bytes::Bytes as axum_core::extract::FromRequest>::from_request would not, by default, set a limit for the size of the r...
CVE-2022-20364HIGH7.8In sysmmu_unmap of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local ...
CVE-2022-20231MEDIUM6.7In smc_intc_request_fiq of arm_gic.c, there is a possible out of bounds write due to improper input validation. This cou...
CVE-2022-3202HIGH7.1A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This coul...
CVE-2022-38796MEDIUM6.1A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be...
CVE-2022-22520MEDIUM5.3A remote, unauthenticated attacker can enumerate valid users by sending specific requests to the webservice of MB connec...
CVE-2022-37661CRITICAL9.8SmartRG SR506n 2.5.15 and SR510n 2.6.13 routers are vulnerable to Remote Code Execution (RCE) via the ping host feature.
CVE-2022-40674HIGH8.1libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now