2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-21950 | MEDIUM | 5.3 | 0.1% | Sep 7, 2022 | A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backpo... |
| CVE-2022-38530 | HIGH | 7.8 | 0.4% | Sep 6, 2022 | GPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflow when processing ISOM_IOD. |
| CVE-2022-38529 | HIGH | 7.8 | 0.3% | Sep 6, 2022 | tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress. |
| CVE-2022-38528 | MEDIUM | 6.5 | 0.6% | Sep 6, 2022 | Open Asset Import Library (assimp) commit 3c253ca was discovered to contain a segmentation violation via the component A... |
| CVE-2022-37344 | CRITICAL | 9.8 | 0.7% | Sep 6, 2022 | Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at WordPress. |
| CVE-2022-36427 | CRITICAL | 9.8 | 0.7% | Sep 6, 2022 | Missing Access Control vulnerability in About Rentals. Inc. About Rentals plugin <= 1.5 at WordPress. |
| CVE-2022-36387 | CRITICAL | 9.8 | 0.7% | Sep 6, 2022 | Broken Access Control vulnerability in Alessio Caiazza's About Me plugin <= 1.0.12 at WordPress. |
| CVE-2022-35913 | MEDIUM | 4.3 | 0.6% | Sep 6, 2022 | Samourai Wallet Stonewallx2 0.99.98e allows a denial of service via a P2P coinjoin. The attacker and victim must follow ... |
| CVE-2022-1525 | CRITICAL | 9.1 | 0.7% | Sep 6, 2022 | The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-602: Client-Side... |
| CVE-2022-1522 | MEDIUM | 5.3 | 0.5% | Sep 6, 2022 | The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-117: Improper Ou... |
| CVE-2022-1368 | CRITICAL | 9.8 | 0.8% | Sep 6, 2022 | The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Aut... |
| CVE-2022-36067 | CRITICAL | 10 | 47.9% | Sep 6, 2022 | vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.... |
| CVE-2022-38176 | HIGH | 7.8 | 0.4% | Sep 6, 2022 | An issue was discovered in YSoft SAFEQ 6 before 6.0.72. Incorrect privileges were configured as part of the installer pa... |
| CVE-2022-36663 | CRITICAL | 9.8 | 1.9% | Sep 6, 2022 | Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted req... |
| CVE-2022-36072 | MEDIUM | 5.9 | 0.5% | Sep 6, 2022 | SilverwareGames.io is a social network for users to play video games online. In version 1.1.8 and prior, due to an unobv... |
| CVE-2022-36065 | HIGH | 7.5 | 1.1% | Sep 6, 2022 | GrowthBook is an open-source platform for feature flagging and A/B testing. With some self-hosted configurations in vers... |
| CVE-2022-36064 | HIGH | 7.5 | 1.1% | Sep 6, 2022 | Shescape is a shell escape package for JavaScript. An Inefficient Regular Expression Complexity vulnerability impacts us... |
| CVE-2022-36061 | CRITICAL | 9.8 | 1.0% | Sep 6, 2022 | Elrond go is the go implementation for the Elrond Network protocol. In versions prior to 1.3.35, read only calls between... |
| CVE-2022-26861 | HIGH | 7.8 | 0.2% | Sep 6, 2022 | Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated malicious user could ... |
| CVE-2022-26860 | HIGH | 7.8 | 0.2% | Sep 6, 2022 | Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could exploit this vulnerabilit... |
| CVE-2022-26859 | HIGH | 7 | 0.1% | Sep 6, 2022 | Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability by sending maliciou... |
| CVE-2022-26858 | HIGH | 7.8 | 0.2% | Sep 6, 2022 | Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potent... |
| CVE-2022-3134 | HIGH | 7.8 | 0.5% | Sep 6, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0389. |
| CVE-2022-37253 | MEDIUM | 5.4 | 0.6% | Sep 6, 2022 | Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 allows a remote attacker to introduce arbitary Javas... |
| CVE-2022-37185 | HIGH | 7.5 | 0.7% | Sep 6, 2022 | SQL injection vulnerability exists in the school information query interface (repschoolproj.php) of the EMS 6.2 system o... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now