2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-49762MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ntfs: check overflow when iterating ATTR_RECORDs K...
CVE-2022-42450MEDIUM5.4Improper sanitization of SVG files in HCL Domino Volt allows client-side script injection in deployed applications.
CVE-2022-42449MEDIUM5.4Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript...
CVE-2022-27562MEDIUM5.4Unsafe default file type filter policy in HCL Domino Volt allows upload of .html file and execution of unsafe JavaScript...
CVE-2022-41871HIGH8.8SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute ...
CVE-2022-44760MEDIUM4.6Unsafe default file type filter policy in HCL Leap allows execution of unsafe JavaScript in deployed applications.
CVE-2022-44759MEDIUM5.4Improper sanitization of SVG files in HCL Leap allows client-side script injection in deployed applications.
CVE-2022-47112LOW3.37-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later ...
CVE-2022-47111LOW3.37-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later v...
CVE-2022-26323HIGH8.7Incorrect Use of Privileged APIs vulnerability in OpenText™ Operations Bridge Manager, OpenText™ Operations Bridge Suite...
CVE-2022-43852MEDIUM5.3IBM Aspera Console 3.4.0 through 3.4.4 could disclose sensitive information in HTTP headers that could be used in furthe...
CVE-2022-43851HIGH7.5IBM Aspera Console 3.4.0 through 3.4.4 uses weaker than expected cryptographic algorithms that could allow an attacker ...
CVE-2022-43850MEDIUM5.4IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed ...
CVE-2022-43847MEDIUM5.4IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to HTTP header injection, caused by improper validation of input ...
CVE-2022-43840MEDIUM4.3IBM Aspera Console 3.4.0 through 3.4.4 is vulnerable to an XPath injection vulnerability, which could allow an authenti...
CVE-2022-49761HIGH7.8In the Linux kernel, the following vulnerability has been resolved: btrfs: always report error in run_one_delayed_ref()...
CVE-2022-49760MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix PTE marker handling in hugetlb_chan...
CVE-2022-49759MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: VMCI: Use threaded irqs instead of tasklets The vm...
CVE-2022-49758MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: reset: uniphier-glue: Fix possible null-ptr-deref ...
CVE-2022-49757MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: EDAC/highbank: Fix memory leak in highbank_mc_probe...
CVE-2022-49756MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: phy: usb: sunplus: Fix potential null-ptr-deref in ...
CVE-2022-49755HIGH7.8In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Prevent race during ffs_ep0_queu...
CVE-2022-49754HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix a buffer overflow in mgmt_mesh_add()...
CVE-2022-49753HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dmaengine: Fix double increment of client_count in ...
CVE-2022-49752MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: device property: fix of node refcount leak in fwnod...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now