2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22101MEDIUM5.5Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdr...
CVE-2022-22100HIGH7.8Memory corruption in multimedia due to improper check on received export descriptors in Snapdragon Auto
CVE-2022-22099HIGH7.8Memory corruption in multimedia due to improper validation of array index in Snapdragon Auto
CVE-2022-22098HIGH7.8Memory corruption in multimedia driver due to untrusted pointer dereference while reading data from socket in Snapdragon...
CVE-2022-22097HIGH7.8Memory corruption in graphic driver due to use after free while calling multiple threads application to driver. in Snapd...
CVE-2022-22096CRITICAL9.8Memory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length pa...
CVE-2022-22080HIGH7.8Improper validation of backend id in PCM routing process can lead to memory corruption in Snapdragon Auto, Snapdragon Co...
CVE-2022-22070HIGH7.8Memory corruption in audio due to lack of check of invalid routing address into APR Routing table in Snapdragon Auto, Sn...
CVE-2022-22069HIGH7.8Devices with keyprotect off may store unencrypted keybox in RPMB and cause cryptographic issue in Snapdragon Auto, Snapd...
CVE-2022-22067HIGH7.8Potential memory leak in modem during the processing of NSA RRC Reconfiguration with invalid Radio Bearer Config in Snap...
CVE-2022-22062CRITICAL9.1An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snap...
CVE-2022-22061HIGH7.8Out of bounds writing is possible while verifying device IDs due to improper length check before copying the data in Sna...
CVE-2022-22059HIGH7.8Memory corruption due to out of bound read while parsing a video file in Snapdragon Auto, Snapdragon Compute, Snapdragon...
CVE-2022-38170MEDIUM4.7In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the...
CVE-2022-38054CRITICAL9.8In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixa...
CVE-2022-29158HIGH7.5Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles ...
CVE-2022-29063CRITICAL9.8The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In...
CVE-2022-25813HIGH7.5In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can ins...
CVE-2022-25371CRITICAL9.8Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and re...
CVE-2022-25370MEDIUM5.4Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. I...
CVE-2022-39194MEDIUM4.9An issue was discovered in the MediaWiki through 1.38.2. The community configuration pages for the GrowthExperiments ext...
CVE-2022-39190MEDIUM5.5An issue was discovered in net/netfilter/nf_tables_api.c in the Linux kernel before 5.19.6. A denial of service can occu...
CVE-2022-39189HIGH7.8An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromis...
CVE-2022-39188MEDIUM4.7An issue was discovered in include/asm-generic/tlb.h in the Linux kernel before 5.19. Because of a race condition (unmap...
CVE-2022-37679MEDIUM4.8Miniblog.Core v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blog/edit. Thi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now