2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-38751 | MEDIUM | 6.5 | 1.5% | Sep 5, 2022 | Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run... |
| CVE-2022-38750 | MEDIUM | 5.5 | 1.0% | Sep 5, 2022 | Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run... |
| CVE-2022-38749 | MEDIUM | 6.5 | 1.6% | Sep 5, 2022 | Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is run... |
| CVE-2022-38370 | HIGH | 7.5 | 1.1% | Sep 5, 2022 | Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal... |
| CVE-2022-38369 | HIGH | 8.8 | 1.1% | Sep 5, 2022 | Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses t... |
| CVE-2022-3008 | HIGH | 8.8 | 2.8% | Sep 5, 2022 | The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are pr... |
| CVE-2022-3120 | CRITICAL | 9.8 | 0.6% | Sep 5, 2022 | A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System. Affected by this v... |
| CVE-2022-39843 | HIGH | 7.8 | 0.4% | Sep 5, 2022 | 123elf Lotus 1-2-3 before 1.0.0rc3 for Linux, and Lotus 1-2-3 R3 for UNIX and other platforms through 9.8.2, allow attac... |
| CVE-2022-39842 | MEDIUM | 6.1 | 0.6% | Sep 5, 2022 | An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the co... |
| CVE-2022-39051 | HIGH | 8.8 | 0.7% | Sep 5, 2022 | Attacker might be able to execute malicious Perl code in the Template toolkit, by having the admin installing an unverif... |
| CVE-2022-39050 | MEDIUM | 4.8 | 0.5% | Sep 5, 2022 | An attacker who is logged into OTRS as an admin user may manipulate customer URL field to store JavaScript code to be ru... |
| CVE-2022-39049 | MEDIUM | 4.8 | 0.5% | Sep 5, 2022 | An attacker who is logged into OTRS as an admin user may manipulate the URL to cause execution of JavaScript in the cont... |
| CVE-2022-39840 | MEDIUM | 4.8 | 0.4% | Sep 5, 2022 | Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a direct message (DM). |
| CVE-2022-39839 | MEDIUM | 4.8 | 0.4% | Sep 5, 2022 | Cotonti Siena 0.9.20 allows admins to conduct stored XSS attacks via a forum post. |
| CVE-2022-39832 | HIGH | 7.8 | 0.5% | Sep 5, 2022 | An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/ps... |
| CVE-2022-39831 | HIGH | 7.8 | 0.5% | Sep 5, 2022 | An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in util... |
| CVE-2022-39830 | HIGH | 7.5 | 1.0% | Sep 5, 2022 | sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_public_key_affine_coo... |
| CVE-2022-39829 | HIGH | 7.5 | 1.0% | Sep 5, 2022 | There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the retu... |
| CVE-2022-39828 | HIGH | 7.5 | 1.0% | Sep 5, 2022 | sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_private_key, leading ... |
| CVE-2022-39824 | HIGH | 8.9 | 0.9% | Sep 5, 2022 | Server-side JavaScript injection in Appsmith through 1.7.14 allows remote attackers to execute arbitrary JavaScript code... |
| CVE-2022-39196 | MEDIUM | 6.5 | 1.1% | Sep 5, 2022 | Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and t... |
| CVE-2022-3118 | CRITICAL | 9.8 | 0.7% | Sep 4, 2022 | A vulnerability was found in Sourcecodehero ERP System Project. It has been rated as critical. This issue affects some u... |
| CVE-2022-3099 | HIGH | 7.8 | 0.5% | Sep 3, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0360. |
| CVE-2022-36754 | HIGH | 7.2 | 0.7% | Sep 2, 2022 | Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/deb... |
| CVE-2022-36647 | MEDIUM | 5.5 | 0.3% | Sep 2, 2022 | PKUVCL davs2 v1.6.205 was discovered to contain a global buffer overflow via the function parse_sequence_header() at sou... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now