2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36642CRITICAL9.8A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 all...
CVE-2022-36640CRITICAL9.8influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers ...
CVE-2022-36639MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in /client.php of Garage Management System v1.0 allows attackers to ex...
CVE-2022-36638MEDIUM5.3An access control issue in the component print.php of Garage Management System v1.0 allows unauthenticated attackers to ...
CVE-2022-31176HIGH8.1Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headles...
CVE-2022-35933MEDIUM6.1This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where ...
CVE-2022-31196HIGH7.5Databasir is a database metadata management platform. Databasir <= 1.06 has Server-Side Request Forgery (SSRF) vulnerabi...
CVE-2022-31152HIGH7.5Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specificatio...
CVE-2022-3065HIGH7.5Improper Access Control in GitHub repository jgraph/drawio prior to 20.2.8.
CVE-2022-36071HIGH8.1SFTPGo is configurable SFTP server with optional HTTP/S, FTP/S and WebDAV support. SFTPGo WebAdmin and WebClient support...
CVE-2022-34382HIGH7.8Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vuln...
CVE-2022-34378MEDIUM5.5Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative p...
CVE-2022-34371CRITICAL9.8Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.19, 9.2.1.12, 9.3.0.6, and 9.4.0.3, contain an unprotect...
CVE-2022-34369HIGH7.5Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3 , contain an insertio...
CVE-2022-36078HIGH7.5Binary provides encoding/decoding in Borsh and other formats. The vulnerability is a memory allocation vulnerability tha...
CVE-2022-36076HIGH7.5NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unne...
CVE-2022-37458HIGH7.2Discourse through 2.8.7 allows admins to send invitations to arbitrary email addresses at an unlimited rate.
CVE-2022-25680HIGH7.8Memory corruption in multimedia due to buffer overflow while processing count variable from client in Snapdragon Auto
CVE-2022-25668CRITICAL9.8Memory corruption in video driver due to double free while parsing ASF clip in Snapdragon Auto, Snapdragon Compute, Snap...
CVE-2022-25659CRITICAL9.8Memory corruption due to buffer overflow while parsing MKV clips with invalid bitmap size in Snapdragon Auto, Snapdragon...
CVE-2022-25658CRITICAL9.8Memory corruption due to incorrect pointer arithmetic when attempting to change the endianness in video parser function ...
CVE-2022-25657CRITICAL9.8Memory corruption due to buffer overflow occurs while processing invalid MKV clip which has invalid seek header in Snapd...
CVE-2022-22106HIGH7.8Memory corruption in multimedia due to improper length check while copying the data in Snapdragon Auto
CVE-2022-22104HIGH7.8Memory corruption in multimedia due to improper check on the messages received. in Snapdragon Auto
CVE-2022-22102HIGH7.8Memory corruption in multimedia due to incorrect type conversion while adding data in Snapdragon Auto

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now