2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-23003MEDIUM5.3When computing a shared secret or point multiplication on the NIST P-256 curve that results in an X coordinate of zero, ...
CVE-2022-23002MEDIUM5.3When compressing or decompressing a point on the NIST P-256 elliptic curve with an X coordinate of zero, the resulting o...
CVE-2022-23001MEDIUM5.3When compressing or decompressing elliptic curve points using the Sweet B library, an incorrect choice of sign bit is us...
CVE-2022-35632MEDIUM4.8The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plu...
CVE-2022-35631MEDIUM5.5On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlin...
CVE-2022-35630MEDIUM6.1A cross-site scripting (XSS) issue in generating a collection report made it possible for malicious clients to inject Ja...
CVE-2022-35629MEDIUM5.4Due to a bug in the handling of the communication between the client and server, it was possible for one client, already...
CVE-2022-33881HIGH7.8Parsing a maliciously crafted PRT file can force Autodesk AutoCAD 2023 to read beyond allocated boundaries. This vulnera...
CVE-2022-2579MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Garage Management System 1.0. Affected...
CVE-2022-2578CRITICAL9.8A vulnerability, which was classified as critical, has been found in SourceCodester Garage Management System 1.0. This i...
CVE-2022-2577HIGH8.8A vulnerability classified as critical was found in SourceCodester Garage Management System 1.0. This vulnerability affe...
CVE-2022-27873HIGH7.8An attacker can force the victim’s device to perform arbitrary HTTP requests in WAN through a malicious SVG file being p...
CVE-2022-36123HIGH7.8The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV...
CVE-2022-35643CRITICAL9.1IBM PowerVM VIOS 3.1 could allow a remote attacker to tamper with system configuration or cause a denial of service. IBM...
CVE-2022-2576HIGH7.5In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full hand...
CVE-2022-1277CRITICAL9.4Inavitas Solar Log product has an unauthenticated SQL Injection vulnerability.
CVE-2022-24912HIGH7.5The package github.com/runatlantis/atlantis/server/controllers/events before 0.19.7 are vulnerable to Timing Attack in t...
CVE-2022-1799CRITICAL9.8Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play ...
CVE-2022-36752MEDIUM5.5png2webp v1.0.4 was discovered to contain an out-of-bounds write via the function w2p. This vulnerability is exploitable...
CVE-2022-36234HIGH7.5SimpleNetwork TCP Server commit 29bc615f0d9910eb2f59aa8dff1f54f0e3af4496 was discovered to contain a double free vulnera...
CVE-2022-34558CRITICAL9.8WMAgent v1.3.3rc2 and 1.3.3rc1, reqmgr 2 1.4.1rc5 and 1.4.0rc2, reqmon 1.4.1rc5, and global-workqueue 1.4.1rc5 allows at...
CVE-2022-34557HIGH8.8Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /...
CVE-2022-34556MEDIUM5.5PicoC v3.2.2 was discovered to contain a NULL pointer dereference at variable.c.
CVE-2022-34555CRITICAL9.8TP-LINK TL-R473G 2.0.1 Build 220529 Rel.65574n was discovered to contain a remote code execution vulnerability which is ...
CVE-2022-34580MEDIUM4.8Advanced School Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the addr...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now