2022 CVE Vulnerabilities
27,541 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23003 | MEDIUM | 5.3 | 0.6% | Jul 29, 2022 | When computing a shared secret or point multiplication on the NIST P-256 curve that results in an X coordinate of zero, ... |
| CVE-2022-23002 | MEDIUM | 5.3 | 0.6% | Jul 29, 2022 | When compressing or decompressing a point on the NIST P-256 elliptic curve with an X coordinate of zero, the resulting o... |
| CVE-2022-23001 | MEDIUM | 5.3 | 0.6% | Jul 29, 2022 | When compressing or decompressing elliptic curve points using the Sweet B library, an incorrect choice of sign bit is us... |
| CVE-2022-35632 | MEDIUM | 4.8 | 0.4% | Jul 29, 2022 | The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plu... |
| CVE-2022-35631 | MEDIUM | 5.5 | 0.2% | Jul 29, 2022 | On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlin... |
| CVE-2022-35630 | MEDIUM | 6.1 | 0.4% | Jul 29, 2022 | A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject Ja... |
| CVE-2022-35629 | MEDIUM | 5.4 | 0.4% | Jul 29, 2022 | Due to a bug in the handling of the communication between the client and server, it was possible for one client, already... |
| CVE-2022-33881 | HIGH | 7.8 | 0.4% | Jul 29, 2022 | Parsing a maliciously crafted PRT file can force Autodesk AutoCAD 2023 to read beyond allocated boundaries. This vulnera... |
| CVE-2022-2579 | MEDIUM | 5.4 | 0.5% | Jul 29, 2022 | A vulnerability, which was classified as problematic, was found in SourceCodester Garage Management System 1.0. Affected... |
| CVE-2022-2578 | CRITICAL | 9.8 | 0.6% | Jul 29, 2022 | A vulnerability, which was classified as critical, has been found in SourceCodester Garage Management System 1.0. This i... |
| CVE-2022-2577 | HIGH | 8.8 | 0.6% | Jul 29, 2022 | A vulnerability classified as critical was found in SourceCodester Garage Management System 1.0. This vulnerability affe... |
| CVE-2022-27873 | HIGH | 7.8 | 0.2% | Jul 29, 2022 | An attacker can force the victim’s device to perform arbitrary HTTP requests in WAN through a malicious SVG file being p... |
| CVE-2022-36123 | HIGH | 7.8 | 0.8% | Jul 29, 2022 | The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV... |
| CVE-2022-35643 | CRITICAL | 9.1 | 1.1% | Jul 29, 2022 | IBM PowerVM VIOS 3.1 could allow a remote attacker to tamper with system configuration or cause a denial of service. IBM... |
| CVE-2022-2576 | HIGH | 7.5 | 0.5% | Jul 29, 2022 | In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full hand... |
| CVE-2022-1277 | CRITICAL | 9.4 | 0.7% | Jul 29, 2022 | Inavitas Solar Log product has an unauthenticated SQL Injection vulnerability. |
| CVE-2022-24912 | HIGH | 7.5 | 0.9% | Jul 29, 2022 | The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in t... |
| CVE-2022-1799 | CRITICAL | 9.8 | 0.3% | Jul 29, 2022 | Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play ... |
| CVE-2022-36752 | MEDIUM | 5.5 | 0.4% | Jul 28, 2022 | png2webp v1.0.4 was discovered to contain an out-of-bounds write via the function w2p. This vulnerability is exploitable... |
| CVE-2022-36234 | HIGH | 7.5 | 0.8% | Jul 28, 2022 | SimpleNetwork TCP Server commit 29bc615f0d9910eb2f59aa8dff1f54f0e3af4496 was discovered to contain a double free vulnera... |
| CVE-2022-34558 | CRITICAL | 9.8 | 1.0% | Jul 28, 2022 | WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows at... |
| CVE-2022-34557 | HIGH | 8.8 | 0.8% | Jul 28, 2022 | Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /... |
| CVE-2022-34556 | MEDIUM | 5.5 | 0.3% | Jul 28, 2022 | PicoC v3.2.2 was discovered to contain a NULL pointer dereference at variable.c. |
| CVE-2022-34555 | CRITICAL | 9.8 | 20.5% | Jul 28, 2022 | TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is ... |
| CVE-2022-34580 | MEDIUM | 4.8 | 0.4% | Jul 28, 2022 | Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the addr... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now