2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-28200 | HIGH | 8.2 | 0.2% | Jul 2, 2022 | NVIDIA DGX A100 contains a vulnerability in SBIOS in the BiosCfgTool, where a local user with elevated privileges can re... |
| CVE-2022-32551 | HIGH | 7.5 | 3.9% | Jul 2, 2022 | Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml... |
| CVE-2022-34903 | MEDIUM | 6.5 | 2.1% | Jul 1, 2022 | GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyrin... |
| CVE-2022-32412 | HIGH | 7.2 | 0.8% | Jul 1, 2022 | An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell. |
| CVE-2022-32411 | HIGH | 7.2 | 0.8% | Jul 1, 2022 | An issue in the languages config file of HongCMS v3.0 allows attackers to getshell. |
| CVE-2022-32325 | MEDIUM | 6.5 | 0.8% | Jul 1, 2022 | JPEGOPTIM v1.4.7 was discovered to contain a segmentation violation which is caused by a READ memory access at jpegoptim... |
| CVE-2022-32324 | CRITICAL | 9.8 | 1.0% | Jul 1, 2022 | PDFAlto v0.4 was discovered to contain a heap buffer overflow via the component /pdfalto/src/pdfalto.cc. |
| CVE-2022-32420 | HIGH | 8.8 | 18.6% | Jul 1, 2022 | College Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /College/admin/... |
| CVE-2022-32384 | HIGH | 8.8 | 0.8% | Jul 1, 2022 | Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the security_5g parameter in the function formWif... |
| CVE-2022-32095 | CRITICAL | 9.8 | 1.3% | Jul 1, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orde... |
| CVE-2022-32094 | CRITICAL | 9.8 | 6.3% | Jul 1, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doc... |
| CVE-2022-32093 | CRITICAL | 9.8 | 1.3% | Jul 1, 2022 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adm... |
| CVE-2022-31943 | CRITICAL | 9.8 | 1.2% | Jul 1, 2022 | MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability. |
| CVE-2022-32091 | HIGH | 7.5 | 1.7% | Jul 1, 2022 | MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common... |
| CVE-2022-32089 | HIGH | 7.5 | 1.6% | Jul 1, 2022 | MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_leve... |
| CVE-2022-32088 | HIGH | 7.5 | 1.4% | Jul 1, 2022 | MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Fil... |
| CVE-2022-32087 | HIGH | 7.5 | 1.3% | Jul 1, 2022 | MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args. |
| CVE-2022-32086 | HIGH | 7.5 | 1.2% | Jul 1, 2022 | MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field. |
| CVE-2022-32085 | HIGH | 7.5 | 1.4% | Jul 1, 2022 | MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::clea... |
| CVE-2022-32084 | HIGH | 7.5 | 1.6% | Jul 1, 2022 | MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select. |
| CVE-2022-32083 | HIGH | 7.5 | 1.4% | Jul 1, 2022 | MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cach... |
| CVE-2022-32082 | HIGH | 7.5 | 1.5% | Jul 1, 2022 | MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc. |
| CVE-2022-32081 | HIGH | 7.5 | 1.6% | Jul 1, 2022 | MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase... |
| CVE-2022-25900 | CRITICAL | 9.8 | 3.2% | Jul 1, 2022 | All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature... |
| CVE-2022-25898 | CRITICAL | 9.8 | 0.9% | Jul 1, 2022 | The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now