2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36637MEDIUM5.4Garage Management System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the br...
CVE-2022-36636HIGH8.8Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php...
CVE-2022-36609CRITICAL9.8Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at ...
CVE-2022-36600MEDIUM4.8BlogEngine v3.3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /blogengine/ap...
CVE-2022-39177HIGH8.8BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capab...
CVE-2022-39176HIGH8.8BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c d...
CVE-2022-36594CRITICAL9.8Mapper v4.0.0 to v4.2.0 was discovered to contain a SQL injection vulnerability via the ids parameter at the selectByIds...
CVE-2022-36593MEDIUM6.5kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /cont...
CVE-2022-39170HIGH8.8libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
CVE-2022-36759CRITICAL9.8Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?r...
CVE-2022-3078MEDIUM5.5An issue was discovered in the Linux kernel through 5.16-rc6. There is a lack of check after calling vzalloc() and lack ...
CVE-2022-38128Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-38127Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-38126Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-36622HIGH7.5Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_...
CVE-2022-36621HIGH7.5Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_...
CVE-2022-36604HIGH7.5An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily ...
CVE-2022-36603HIGH8.8InnoSilicon T3T+ t2t+_soc_20190911_151433.swu was discovered to contain a remote code execution (RCE) vulnerability in t...
CVE-2022-36602HIGH8.8InnoSilicon A10 a10_20200924_120556 was discovered to contain a remote code execution (RCE) vulnerability in the setPlat...
CVE-2022-36601CRITICAL9.8The Eclipse TCF debug interface in JasMiner-X4-Server-20220621-090907 and below is open on port 1534. This issue allows ...
CVE-2022-32743HIGH7.5Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged ...
CVE-2022-2806MEDIUM5.5It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8...
CVE-2022-2764MEDIUM4.9A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for ...
CVE-2022-2739MEDIUM5.3The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrec...
CVE-2022-2738HIGH7.5The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrec...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now