2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26331 | MEDIUM | 6.1 | 0.4% | Aug 31, 2022 | Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exp... |
| CVE-2022-26330 | HIGH | 7.5 | 0.5% | Aug 31, 2022 | Potential vulnerabilities have been identified in Micro Focus ArcSight Logger. The vulnerabilities could be remotely exp... |
| CVE-2022-21941 | CRITICAL | 9.8 | 2.0% | Aug 31, 2022 | All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauth... |
| CVE-2022-1976 | HIGH | 7.8 | 0.2% | Aug 31, 2022 | A flaw was found in the Linux kernel’s implementation of IO-URING. This flaw allows an attacker with local executable pe... |
| CVE-2022-1975 | MEDIUM | 5.5 | 0.2% | Aug 31, 2022 | There is a sleep-in-atomic bug in /net/nfc/netlink.c that allows an attacker to crash the Linux kernel by simulating a n... |
| CVE-2022-1974 | MEDIUM | 4.1 | 0.1% | Aug 31, 2022 | A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject cre... |
| CVE-2022-1888 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | Alpha7 PC Loader (All versions) is vulnerable to a stack-based buffer overflow while processing a specifically crafted p... |
| CVE-2022-1552 | HIGH | 8.8 | 11.7% | Aug 31, 2022 | A flaw was found in PostgreSQL. There is an issue with incomplete efforts to operate safely when a privileged user is ma... |
| CVE-2022-1508 | MEDIUM | 6.1 | 0.2% | Aug 31, 2022 | An out-of-bounds read flaw was found in the Linux kernel’s io_uring module in the way a user triggers the io_read() func... |
| CVE-2022-1405 | HIGH | 7.8 | 2.2% | Aug 31, 2022 | CNCSoft: All versions prior to 1.01.32 does not properly sanitize input while processing a specific project file, allowi... |
| CVE-2022-1404 | HIGH | 7.1 | 0.3% | Aug 31, 2022 | Delta Electronics CNCSoft (All versions prior to 1.01.32) does not properly sanitize input while processing a specific p... |
| CVE-2022-1355 | MEDIUM | 6.1 | 0.5% | Aug 31, 2022 | A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a ... |
| CVE-2022-1354 | MEDIUM | 5.5 | 0.5% | Aug 31, 2022 | A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an ... |
| CVE-2022-1325 | MEDIUM | 5.5 | 0.4% | Aug 31, 2022 | A flaw was found in Clmg, where with the help of a maliciously crafted pandore or bmp file with modified dx and dy heade... |
| CVE-2022-1319 | HIGH | 7.5 | 1.2% | Aug 31, 2022 | A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packe... |
| CVE-2022-1271 | HIGH | 8.8 | 4.1% | Aug 31, 2022 | An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's cho... |
| CVE-2022-1263 | MEDIUM | 5.5 | 0.4% | Aug 31, 2022 | A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allow... |
| CVE-2022-1259 | HIGH | 7.5 | 1.0% | Aug 31, 2022 | A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause o... |
| CVE-2022-1247 | HIGH | 7 | 0.3% | Aug 31, 2022 | An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh->use to... |
| CVE-2022-1205 | MEDIUM | 4.7 | 0.4% | Aug 31, 2022 | A NULL pointer dereference flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a ... |
| CVE-2022-36045 | CRITICAL | 9.8 | 1.0% | Aug 31, 2022 | NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes we... |
| CVE-2022-36035 | HIGH | 7.8 | 0.3% | Aug 31, 2022 | Flux is a tool for keeping Kubernetes clusters in sync with sources of configuration (like Git repositories), and automa... |
| CVE-2022-27911 | MEDIUM | 5.3 | 0.5% | Aug 31, 2022 | An issue was discovered in Joomla! 4.2.0. Multiple Full Path Disclosures because of missing '_JEXEC or die check' caused... |
| CVE-2022-37023 | MEDIUM | 6.5 | 1.3% | Aug 31, 2022 | Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on ... |
| CVE-2022-37022 | HIGH | 8.8 | 1.2% | Aug 31, 2022 | Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now