2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-38751MEDIUM6.5Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run...
CVE-2022-38750MEDIUM5.5Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run...
CVE-2022-38749MEDIUM6.5Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run...
CVE-2022-38370HIGH7.5Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal...
CVE-2022-38369HIGH8.8Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses t...
CVE-2022-3008HIGH8.8The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are pr...
CVE-2022-3120CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System. Affected by this v...
CVE-2022-39843HIGH7.8123elf Lotus 1-2-3 before 1.0.0rc3 for Linux, and Lotus 1-2-3 R3 for UNIX and other platforms through 9.8.2, allow attac...
CVE-2022-39842MEDIUM6.1An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the co...
CVE-2022-39051HIGH8.8Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverif...
CVE-2022-39050MEDIUM4.8An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be ru...
CVE-2022-39049MEDIUM4.8An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the cont...
CVE-2022-39840MEDIUM4.8Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a direct message (DM).
CVE-2022-39839MEDIUM4.8Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a forum post.
CVE-2022-39832HIGH7.8An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/ps...
CVE-2022-39831HIGH7.8An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in util...
CVE-2022-39830HIGH7.5sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_public_key_affine_coo...
CVE-2022-39829HIGH7.5There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the retu...
CVE-2022-39828HIGH7.5sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_private_key, leading ...
CVE-2022-39824HIGH8.9Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code...
CVE-2022-39196MEDIUM6.5Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and t...
CVE-2022-3118CRITICAL9.8A vulnerability was found in Sourcecodehero ERP System Project. It has been rated as critical. This issue affects some u...
CVE-2022-3099HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0360.
CVE-2022-36754HIGH7.2Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/deb...
CVE-2022-36647MEDIUM5.5PKUVCL davs2 v1.6.205 was discovered to contain a global buffer overflow via the function parse_sequence_header() at sou...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now