2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25655 | HIGH | 7.8 | 0.1% | Mar 10, 2023 | Memory corruption in WLAN HAL while arbitrary value is passed in WMI UTF command payload. |
| CVE-2022-20929 | HIGH | 7.8 | 0.2% | Mar 10, 2023 | A vulnerability in the upgrade signature verification of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allo... |
| CVE-2022-4331 | HIGH | 7.3 | 0.7% | Mar 9, 2023 | An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting... |
| CVE-2022-46394 | HIGH | 8.8 | 0.7% | Mar 8, 2023 | An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operat... |
| CVE-2022-42476 | HIGH | 8.2 | 0.2% | Mar 7, 2023 | A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 an... |
| CVE-2022-41333 | HIGH | 7.5 | 7.2% | Mar 7, 2023 | An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below ... |
| CVE-2022-41328 | HIGH | 7.1 | 12.3% | Mar 7, 2023 | A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet Fort... |
| CVE-2022-39953 | HIGH | 7.8 | 0.2% | Mar 7, 2023 | A improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, ... |
| CVE-2022-39951 | HIGH | 8.8 | 1.8% | Mar 7, 2023 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio... |
| CVE-2022-4904 | HIGH | 8.6 | 1.2% | Mar 6, 2023 | A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, ... |
| CVE-2022-45142 | HIGH | 7.5 | 0.5% | Mar 6, 2023 | The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!=... |
| CVE-2022-3424 | HIGH | 7.8 | 0.2% | Mar 6, 2023 | A use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl functi... |
| CVE-2022-4265 | HIGH | 8.8 | 0.5% | Mar 6, 2023 | The Replyable WordPress plugin before 2.2.10 does not validate the class name submitted by the request when instantiatin... |
| CVE-2022-46395 | HIGH | 8.8 | 2.7% | Mar 6, 2023 | An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operat... |
| CVE-2022-4862 | HIGH | 7.6 | 0.4% | Mar 6, 2023 | Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. Thi... |
| CVE-2022-3284 | HIGH | 7.5 | 0.7% | Mar 6, 2023 | Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Fil... |
| CVE-2022-47665 | HIGH | 7.8 | 0.3% | Mar 3, 2023 | Libde265 1.0.9 has a heap buffer overflow vulnerability in de265_image::set_SliceAddrRS(int, int, int) |
| CVE-2022-47664 | HIGH | 7.8 | 0.3% | Mar 3, 2023 | Libde265 1.0.9 is vulnerable to Buffer Overflow in ff_hevc_put_hevc_qpel_pixels_8_sse |
| CVE-2022-45988 | HIGH | 7.8 | 0.4% | Mar 3, 2023 | starsoftcomm CooCare 5.304 allows local attackers to escalate privileges and execute arbitrary commands via a crafted fi... |
| CVE-2022-45552 | HIGH | 7.5 | 0.8% | Mar 3, 2023 | An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to ... |
| CVE-2022-38734 | HIGH | 7.5 | 0.6% | Mar 2, 2023 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0.8 are susceptible to a Denial of Service (DoS) vuln... |
| CVE-2022-3294 | HIGH | 8.8 | 1.6% | Mar 1, 2023 | Users may have access to secure endpoints in the control plane network. Kubernetes clusters are only affected if an untr... |
| CVE-2022-45608 | HIGH | 8.8 | 0.9% | Mar 1, 2023 | An issue was discovered in ThingsBoard 3.4.1, allows low privileged attackers (CUSTOMER_USER) to gain escalated privileg... |
| CVE-2022-45068 | HIGH | 8.8 | 0.3% | Mar 1, 2023 | Cross-Site Request Forgery (CSRF) vulnerability in Mercado Pago Mercado Pago payments for WooCommerce plugin <= 6.3.1. |
| CVE-2022-27677 | HIGH | 7.8 | 0.2% | Mar 1, 2023 | Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to mo... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now