2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36637 | MEDIUM | 5.4 | 0.5% | Sep 2, 2022 | Garage Management System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the br... |
| CVE-2022-36636 | HIGH | 8.8 | 0.9% | Sep 2, 2022 | Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php... |
| CVE-2022-36609 | CRITICAL | 9.8 | 0.6% | Sep 2, 2022 | Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ... |
| CVE-2022-36600 | MEDIUM | 4.8 | 0.4% | Sep 2, 2022 | BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/ap... |
| CVE-2022-39177 | HIGH | 8.8 | 0.6% | Sep 2, 2022 | BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capab... |
| CVE-2022-39176 | HIGH | 8.8 | 0.7% | Sep 2, 2022 | BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c d... |
| CVE-2022-36594 | CRITICAL | 9.8 | 0.7% | Sep 2, 2022 | Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds... |
| CVE-2022-36593 | MEDIUM | 6.5 | 0.7% | Sep 2, 2022 | kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /cont... |
| CVE-2022-39170 | HIGH | 8.8 | 0.9% | Sep 2, 2022 | libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c. |
| CVE-2022-36759 | CRITICAL | 9.8 | 0.9% | Sep 2, 2022 | Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?r... |
| CVE-2022-3078 | MEDIUM | 5.5 | 0.2% | Sep 1, 2022 | An issue was discovered in the Linux kernel through 5.16-rc6. There is a lack of check after calling vzalloc() and lack ... |
| CVE-2022-38128 | — | — | — | Sep 1, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-38127 | — | — | — | Sep 1, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-38126 | — | — | — | Sep 1, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-36622 | HIGH | 7.5 | 1.1% | Sep 1, 2022 | Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_... |
| CVE-2022-36621 | HIGH | 7.5 | 1.1% | Sep 1, 2022 | Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_... |
| CVE-2022-36604 | HIGH | 7.5 | 0.6% | Sep 1, 2022 | An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily ... |
| CVE-2022-36603 | HIGH | 8.8 | 1.4% | Sep 1, 2022 | InnoSilicon T3T+ t2t+_soc_20190911_151433.swu was discovered to contain a remote code execution (RCE) vulnerability in t... |
| CVE-2022-36602 | HIGH | 8.8 | 1.4% | Sep 1, 2022 | InnoSilicon A10 a10_20200924_120556 was discovered to contain a remote code execution (RCE) vulnerability in the setPlat... |
| CVE-2022-36601 | CRITICAL | 9.8 | 1.0% | Sep 1, 2022 | The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows ... |
| CVE-2022-32743 | HIGH | 7.5 | 1.1% | Sep 1, 2022 | Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged ... |
| CVE-2022-2806 | MEDIUM | 5.5 | 0.2% | Sep 1, 2022 | It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8... |
| CVE-2022-2764 | MEDIUM | 4.9 | 0.8% | Sep 1, 2022 | A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for ... |
| CVE-2022-2739 | MEDIUM | 5.3 | 0.4% | Sep 1, 2022 | The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrec... |
| CVE-2022-2738 | HIGH | 7.5 | 0.7% | Sep 1, 2022 | The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrec... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now