2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-21950MEDIUM5.3A Improper Access Control vulnerability in the systemd service of cana in openSUSE Backports SLE-15-SP3, openSUSE Backpo...
CVE-2022-38530HIGH7.8GPAC v2.1-DEV-rev232-gfcaa01ebb-master was discovered to contain a stack overflow when processing ISOM_IOD.
CVE-2022-38529HIGH7.8tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress.
CVE-2022-38528MEDIUM6.5Open Asset Import Library (assimp) commit 3c253ca was discovered to contain a segmentation violation via the component A...
CVE-2022-37344CRITICAL9.8Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at WordPress.
CVE-2022-36427CRITICAL9.8Missing Access Control vulnerability in About Rentals. Inc. About Rentals plugin <= 1.5 at WordPress.
CVE-2022-36387CRITICAL9.8Broken Access Control vulnerability in Alessio Caiazza's About Me plugin <= 1.0.12 at WordPress.
CVE-2022-35913MEDIUM4.3Samourai Wallet Stonewallx2 0.99.98e allows a denial of service via a P2P coinjoin. The attacker and victim must follow ...
CVE-2022-1525CRITICAL9.1The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-602: Client-Side...
CVE-2022-1522MEDIUM5.3The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-117: Improper Ou...
CVE-2022-1368CRITICAL9.8The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Aut...
CVE-2022-36067CRITICAL10vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9....
CVE-2022-38176HIGH7.8An issue was discovered in YSoft SAFEQ 6 before 6.0.72. Incorrect privileges were configured as part of the installer pa...
CVE-2022-36663CRITICAL9.8Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted req...
CVE-2022-36072MEDIUM5.9SilverwareGames.io is a social network for users to play video games online. In version 1.1.8 and prior, due to an unobv...
CVE-2022-36065HIGH7.5GrowthBook is an open-source platform for feature flagging and A/B testing. With some self-hosted configurations in vers...
CVE-2022-36064HIGH7.5Shescape is a shell escape package for JavaScript. An Inefficient Regular Expression Complexity vulnerability impacts us...
CVE-2022-36061CRITICAL9.8Elrond go is the go implementation for the Elrond Network protocol. In versions prior to 1.3.35, read only calls between...
CVE-2022-26861HIGH7.8Dell BIOS versions contain an Insecure Automated Optimization vulnerability. A local authenticated malicious user could ...
CVE-2022-26860HIGH7.8Dell BIOS versions contain a stack-based buffer overflow vulnerability. A local attacker could exploit this vulnerabilit...
CVE-2022-26859HIGH7Dell BIOS contains a race condition vulnerability. A local attacker could exploit this vulnerability by sending maliciou...
CVE-2022-26858HIGH7.8Dell BIOS versions contain an Improper Authentication vulnerability. A locally authenticated malicious user could potent...
CVE-2022-3134HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0389.
CVE-2022-37253MEDIUM5.4Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 allows a remote attacker to introduce arbitary Javas...
CVE-2022-37185HIGH7.5SQL injection vulnerability exists in the school information query interface (repschoolproj.php) of the EMS 6.2 system o...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now