2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-20345HIGH8.8In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This cou...
CVE-2022-20344HIGH7In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communication due to a race...
CVE-2022-20239CRITICAL9.8remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->vm...
CVE-2022-1962MEDIUM5.5Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a ...
CVE-2022-1705MEDIUM6.5Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 al...
CVE-2022-35715HIGH7.5IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec...
CVE-2022-35280CRITICAL9.8IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by de...
CVE-2022-34365MEDIUM6.5WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability,...
CVE-2022-33931MEDIUM5.3Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An attacker with no ...
CVE-2022-33930HIGH7.5Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could pot...
CVE-2022-33929MEDIUM6.1Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in EndUserSummary pag...
CVE-2022-33928HIGH8.8Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with...
CVE-2022-33927MEDIUM6.5Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could e...
CVE-2022-33926MEDIUM6.5Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user co...
CVE-2022-33925MEDIUM6.5Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authentica...
CVE-2022-33924MEDIUM5.3Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability with which an attacker with...
CVE-2022-29090MEDIUM6.5Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious ...
CVE-2022-22490MEDIUM4.9IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot cr...
CVE-2022-22411MEDIUM6.5IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow...
CVE-2022-22369HIGH7.1IBM Workload Scheduler 9.4 and 9.5 could allow a local user to overwrite key system files which would cause the system t...
CVE-2022-20866HIGH7.5A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisc...
CVE-2022-20713MEDIUM6.1A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco F...
CVE-2022-38133MEDIUM5.3In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
CVE-2022-2756MEDIUM6.5Server-Side Request Forgery (SSRF) in GitHub repository kareadita/kavita prior to 0.5.4.1.
CVE-2022-0028HIGH8.6A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified T...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now