2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28200HIGH8.2NVIDIA DGX A100 contains a vulnerability in SBIOS in the BiosCfgTool, where a local user with elevated privileges can re...
CVE-2022-32551HIGH7.5Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml...
CVE-2022-34903MEDIUM6.5GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyrin...
CVE-2022-32412HIGH7.2An issue in the /template/edit component of HongCMS v3.0 allows attackers to getshell.
CVE-2022-32411HIGH7.2An issue in the languages config file of HongCMS v3.0 allows attackers to getshell.
CVE-2022-32325MEDIUM6.5JPEGOPTIM v1.4.7 was discovered to contain a segmentation violation which is caused by a READ memory access at jpegoptim...
CVE-2022-32324CRITICAL9.8PDFAlto v0.4 was discovered to contain a heap buffer overflow via the component /pdfalto/src/pdfalto.cc.
CVE-2022-32420HIGH8.8College Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /College/admin/...
CVE-2022-32384HIGH8.8Tenda AC23 v16.03.07.44 was discovered to contain a stack overflow via the security_5g parameter in the function formWif...
CVE-2022-32095CRITICAL9.8Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orde...
CVE-2022-32094CRITICAL9.8Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doc...
CVE-2022-32093CRITICAL9.8Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adm...
CVE-2022-31943CRITICAL9.8MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.
CVE-2022-32091HIGH7.5MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common...
CVE-2022-32089HIGH7.5MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_leve...
CVE-2022-32088HIGH7.5MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Fil...
CVE-2022-32087HIGH7.5MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args.
CVE-2022-32086HIGH7.5MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.
CVE-2022-32085HIGH7.5MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::clea...
CVE-2022-32084HIGH7.5MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.
CVE-2022-32083HIGH7.5MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cach...
CVE-2022-32082HIGH7.5MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.
CVE-2022-32081HIGH7.5MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase...
CVE-2022-25900CRITICAL9.8All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature...
CVE-2022-25898CRITICAL9.8The package jsrsasign before 10.5.25 are vulnerable to Improper Verification of Cryptographic Signature when JWS or JWT ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now