2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-23764CRITICAL9.8The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote a...
CVE-2022-23747CRITICAL9.8In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of ...
CVE-2022-1748HIGH7.5Softing OPC UA C++ Server SDK, Secure Integration Server, edgeConnector, edgeAggregator, OPC Suite, and uaGate are affec...
CVE-2022-1373HIGH7.2The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vu...
CVE-2022-1069HIGH7.5A crafted HTTP packet with a large content-length header can create a denial-of-service condition in Softing Secure Inte...
CVE-2022-36216HIGH7.2DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php.
CVE-2022-36215HIGH7.2DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php.
CVE-2022-35516CRITICAL9.8DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.
CVE-2022-35121CRITICAL9.8Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/Boo...
CVE-2022-2862HIGH7.8Use After Free in GitHub repository vim/vim prior to 9.0.0221.
CVE-2022-2870CRITICAL9.8A vulnerability was found in laravel 5.1 and classified as problematic. This issue affects some unknown processing. The ...
CVE-2022-38392MEDIUM5.3Certain 5400 RPM hard drives, for laptops and other PCs in approximately 2005 and later, allow physically proximate atta...
CVE-2022-35117MEDIUM4.8Clinic's Patient Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via update_...
CVE-2022-2849HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.
CVE-2022-36191MEDIUM5.5A heap-buffer-overflow had occurred in function gf_isom_dovi_config_get of isomedia/avc_ext.c:2490, as demonstrated by M...
CVE-2022-22455CRITICAL9.8IBM Security Verify Governance Identity Manager 10.0 virtual appliance component performs an operation at a privilege le...
CVE-2022-38149HIGH7.5HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returne...
CVE-2022-36190CRITICAL9.8GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulne...
CVE-2022-36186HIGH7.5A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_pro...
CVE-2022-31262HIGH7.8An exploitable local privilege escalation vulnerability exists in GOG Galaxy 2.0.46. Due to insufficient folder permissi...
CVE-2022-30262HIGH7.8The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP...
CVE-2022-2845HIGH7.8Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.
CVE-2022-37459HIGH7.8Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to control the predictions f...
CVE-2022-2871MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository notrinos/notrinoserp prior to 0.7.
CVE-2022-1410HIGH8.8OS Command Injection vulnerability in the db_optimize component of Device42 Asset Management Appliance allows an authent...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now