2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22101 | MEDIUM | 5.5 | 0.1% | Sep 2, 2022 | Denial of service in multimedia due to uncontrolled resource consumption while parsing an incoming HAB message in Snapdr... |
| CVE-2022-22100 | HIGH | 7.8 | 0.1% | Sep 2, 2022 | Memory corruption in multimedia due to improper check on received export descriptors in Snapdragon Auto |
| CVE-2022-22099 | HIGH | 7.8 | 0.1% | Sep 2, 2022 | Memory corruption in multimedia due to improper validation of array index in Snapdragon Auto |
| CVE-2022-22098 | HIGH | 7.8 | 0.1% | Sep 2, 2022 | Memory corruption in multimedia driver due to untrusted pointer dereference while reading data from socket in Snapdragon... |
| CVE-2022-22097 | HIGH | 7.8 | 0.1% | Sep 2, 2022 | Memory corruption in graphic driver due to use after free while calling multiple threads application to driver. in Snapd... |
| CVE-2022-22096 | CRITICAL | 9.8 | 0.4% | Sep 2, 2022 | Memory corruption in Bluetooth HOST due to stack-based buffer overflow when when extracting data using command length pa... |
| CVE-2022-22080 | HIGH | 7.8 | 0.1% | Sep 2, 2022 | Improper validation of backend id in PCM routing process can lead to memory corruption in Snapdragon Auto, Snapdragon Co... |
| CVE-2022-22070 | HIGH | 7.8 | 0.1% | Sep 2, 2022 | Memory corruption in audio due to lack of check of invalid routing address into APR Routing table in Snapdragon Auto, Sn... |
| CVE-2022-22069 | HIGH | 7.8 | 0.1% | Sep 2, 2022 | Devices with keyprotect off may store unencrypted keybox in RPMB and cause cryptographic issue in Snapdragon Auto, Snapd... |
| CVE-2022-22067 | HIGH | 7.8 | 0.3% | Sep 2, 2022 | Potential memory leak in modem during the processing of NSA RRC Reconfiguration with invalid Radio Bearer Config in Snap... |
| CVE-2022-22062 | CRITICAL | 9.1 | 0.3% | Sep 2, 2022 | An out-of-bounds read can occur while parsing a server certificate due to improper length check in Snapdragon Auto, Snap... |
| CVE-2022-22061 | HIGH | 7.8 | 0.1% | Sep 2, 2022 | Out of bounds writing is possible while verifying device IDs due to improper length check before copying the data in Sna... |
| CVE-2022-22059 | HIGH | 7.8 | 0.1% | Sep 2, 2022 | Memory corruption due to out of bound read while parsing a video file in Snapdragon Auto, Snapdragon Compute, Snapdragon... |
| CVE-2022-38170 | MEDIUM | 4.7 | 0.6% | Sep 2, 2022 | In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the... |
| CVE-2022-38054 | CRITICAL | 9.8 | 1.8% | Sep 2, 2022 | In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixa... |
| CVE-2022-29158 | HIGH | 7.5 | 1.7% | Sep 2, 2022 | Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles ... |
| CVE-2022-29063 | CRITICAL | 9.8 | 3.5% | Sep 2, 2022 | The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In... |
| CVE-2022-25813 | HIGH | 7.5 | 67.3% | Sep 2, 2022 | In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can ins... |
| CVE-2022-25371 | CRITICAL | 9.8 | 3.9% | Sep 2, 2022 | Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and re... |
| CVE-2022-25370 | MEDIUM | 5.4 | 1.9% | Sep 2, 2022 | Apache OFBiz uses the Birt plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. I... |
| CVE-2022-39194 | MEDIUM | 4.9 | 0.9% | Sep 2, 2022 | An issue was discovered in the MediaWiki through 1.38.2. The community configuration pages for the GrowthExperiments ext... |
| CVE-2022-39190 | MEDIUM | 5.5 | 0.3% | Sep 2, 2022 | An issue was discovered in net/netfilter/nf_tables_api.c in the Linux kernel before 5.19.6. A denial of service can occu... |
| CVE-2022-39189 | HIGH | 7.8 | 0.3% | Sep 2, 2022 | An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromis... |
| CVE-2022-39188 | MEDIUM | 4.7 | 0.2% | Sep 2, 2022 | An issue was discovered in include/asm-generic/tlb.h in the Linux kernel before 5.19. Because of a race condition (unmap... |
| CVE-2022-37679 | MEDIUM | 4.8 | 0.4% | Sep 2, 2022 | Miniblog.Core v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blog/edit. Thi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now