2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-25655HIGH7.8Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload.
CVE-2022-20929HIGH7.8A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allo...
CVE-2022-4331HIGH7.3An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting...
CVE-2022-46394HIGH8.8An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operat...
CVE-2022-42476HIGH8.2A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 an...
CVE-2022-41333HIGH7.5An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below ...
CVE-2022-41328HIGH7.1A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet Fort...
CVE-2022-39953HIGH7.8A improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, ...
CVE-2022-39951HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio...
CVE-2022-4904HIGH8.6A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, ...
CVE-2022-45142HIGH7.5The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!=...
CVE-2022-3424HIGH7.8A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl functi...
CVE-2022-4265HIGH8.8The Replyable WordPress plugin before 2.2.10 does not validate the class name submitted by the request when instantiatin...
CVE-2022-46395HIGH8.8An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operat...
CVE-2022-4862HIGH7.6Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. Thi...
CVE-2022-3284HIGH7.5Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Fil...
CVE-2022-47665HIGH7.8Libde265 1.0.9 has a heap buffer overflow vulnerability in de265_image::set_SliceAddrRS(int, int, int)
CVE-2022-47664HIGH7.8Libde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_8_sse
CVE-2022-45988HIGH7.8starsoftcomm CooCare 5.304 allows local attackers to escalate privileges and execute arbitrary commands via a crafted fi...
CVE-2022-45552HIGH7.5An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to ...
CVE-2022-38734HIGH7.5StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vuln...
CVE-2022-3294HIGH8.8Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untr...
CVE-2022-45608HIGH8.8An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileg...
CVE-2022-45068HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Mercado Pago Mercado Pago payments for WooCommerce plugin <= 6.3.1.
CVE-2022-27677HIGH7.8 Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to mo...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now