2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-26331MEDIUM6.1Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exp...
CVE-2022-26330HIGH7.5Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exp...
CVE-2022-21941CRITICAL9.8All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauth...
CVE-2022-1976HIGH7.8A flaw was found in the Linux kernel’s implementation of IO-URING. This flaw allows an attacker with local executable pe...
CVE-2022-1975MEDIUM5.5There is a sleep-in-atomic bug in /net/nfc/netlink.c that allows an attacker to crash the Linux kernel by simulating a n...
CVE-2022-1974MEDIUM4.1A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject cre...
CVE-2022-1888HIGH7.8Alpha7 PC Loader (All versions) is vulnerable to a stack-based buffer overflow while processing a specifically crafted p...
CVE-2022-1552HIGH8.8A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is ma...
CVE-2022-1508MEDIUM6.1An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() func...
CVE-2022-1405HIGH7.8CNCSoft: All versions prior to 1.01.32 does not properly sanitize input while processing a specific project file, allowi...
CVE-2022-1404HIGH7.1Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while processing a specific p...
CVE-2022-1355MEDIUM6.1A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a ...
CVE-2022-1354MEDIUM5.5A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an ...
CVE-2022-1325MEDIUM5.5A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy heade...
CVE-2022-1319HIGH7.5A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packe...
CVE-2022-1271HIGH8.8An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's cho...
CVE-2022-1263MEDIUM5.5A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allow...
CVE-2022-1259HIGH7.5A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause o...
CVE-2022-1247HIGH7An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh->use to...
CVE-2022-1205MEDIUM4.7A NULL pointer dereference flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a ...
CVE-2022-36045CRITICAL9.8NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes we...
CVE-2022-36035HIGH7.8Flux is a tool for keeping Kubernetes clusters in sync with sources of configuration (like Git repositories), and automa...
CVE-2022-27911MEDIUM5.3An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused...
CVE-2022-37023MEDIUM6.5Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on ...
CVE-2022-37022HIGH8.8Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now