2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23764 | CRITICAL | 9.8 | 0.5% | Aug 17, 2022 | The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote a... |
| CVE-2022-23747 | CRITICAL | 9.8 | 10.0% | Aug 17, 2022 | In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of ... |
| CVE-2022-1748 | HIGH | 7.5 | 0.9% | Aug 17, 2022 | Softing OPC UA C++ Server SDK, Secure Integration Server, edgeConnector, edgeAggregator, OPC Suite, and uaGate are affec... |
| CVE-2022-1373 | HIGH | 7.2 | 10.2% | Aug 17, 2022 | The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vu... |
| CVE-2022-1069 | HIGH | 7.5 | 1.3% | Aug 17, 2022 | A crafted HTTP packet with a large content-length header can create a denial-of-service condition in Softing Secure Inte... |
| CVE-2022-36216 | HIGH | 7.2 | 1.7% | Aug 17, 2022 | DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php. |
| CVE-2022-36215 | HIGH | 7.2 | 1.7% | Aug 17, 2022 | DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php. |
| CVE-2022-35516 | CRITICAL | 9.8 | 1.9% | Aug 17, 2022 | DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php. |
| CVE-2022-35121 | CRITICAL | 9.8 | 0.8% | Aug 17, 2022 | Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/Boo... |
| CVE-2022-2862 | HIGH | 7.8 | 0.7% | Aug 17, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0221. |
| CVE-2022-2870 | CRITICAL | 9.8 | 0.7% | Aug 17, 2022 | A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The ... |
| CVE-2022-38392 | MEDIUM | 5.3 | 0.4% | Aug 17, 2022 | Certain 5400 RPM hard drives, for laptops and other PCs in approximately 2005 and later, allow physically proximate atta... |
| CVE-2022-35117 | MEDIUM | 4.8 | 0.5% | Aug 17, 2022 | Clinic's Patient Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via update_... |
| CVE-2022-2849 | HIGH | 7.8 | 0.5% | Aug 17, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220. |
| CVE-2022-36191 | MEDIUM | 5.5 | 0.4% | Aug 17, 2022 | A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by M... |
| CVE-2022-22455 | CRITICAL | 9.8 | 0.4% | Aug 17, 2022 | IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege le... |
| CVE-2022-38149 | HIGH | 7.5 | 0.7% | Aug 17, 2022 | HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returne... |
| CVE-2022-36190 | CRITICAL | 9.8 | 0.9% | Aug 17, 2022 | GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulne... |
| CVE-2022-36186 | HIGH | 7.5 | 0.8% | Aug 17, 2022 | A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_pro... |
| CVE-2022-31262 | HIGH | 7.8 | 0.5% | Aug 17, 2022 | An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissi... |
| CVE-2022-30262 | HIGH | 7.8 | 0.2% | Aug 17, 2022 | The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP... |
| CVE-2022-2845 | HIGH | 7.8 | 0.5% | Aug 17, 2022 | Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218. |
| CVE-2022-37459 | HIGH | 7.8 | 0.2% | Aug 17, 2022 | Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions f... |
| CVE-2022-2871 | MEDIUM | 5.4 | 0.5% | Aug 17, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository notrinos/notrinoserp prior to 0.7. |
| CVE-2022-1410 | HIGH | 8.8 | 1.0% | Aug 17, 2022 | OS Command Injection vulnerability in the db_optimize component of Device42 Asset Management Appliance allows an authent... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now