2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2013HIGH7.5In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental f...
CVE-2022-2054HIGH7.8Code Injection in GitHub repository nuitka/nuitka prior to 0.9.
CVE-2022-30780HIGH7.5Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connect...
CVE-2022-32981HIGH7.8An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in pt...
CVE-2022-29095CRITICAL9.6Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 ...
CVE-2022-29094HIGH7.1Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial version...
CVE-2022-29093HIGH7.1Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial version...
CVE-2022-29092HIGH7.8Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial version...
CVE-2022-25863CRITICAL9.8The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted...
CVE-2022-25851HIGH7.5The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause ...
CVE-2022-25845CRITICAL9.8The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the defa...
CVE-2022-24429HIGH7.8The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG ...
CVE-2022-24376CRITICAL9.8All versions of package git-promise are vulnerable to Command Injection due to an inappropriate fix of a prior [vulnerab...
CVE-2022-24278CRITICAL9.8The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags...
CVE-2022-21211HIGH7.5This affects all versions of package posix. When invoking the toString method, it will fallback to 0x0 value, as the val...
CVE-2022-2042HIGH7.8Use After Free in GitHub repository vim/vim prior to 8.2.
CVE-2022-31287MEDIUM5.5An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp.
CVE-2022-31285MEDIUM5.5An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h.
CVE-2022-31282MEDIUM5.5Bento4 MP4Dump v1.2 was discovered to contain a segmentation violation via an unknown address at /Source/C++/Core/Ap4Dat...
CVE-2022-31402MEDIUM6.1ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php.
CVE-2022-29948MEDIUM4.6Due to an insecure design, the Lepin EP-KP001 flash drive through KP001_V19 is vulnerable to an authentication bypass at...
CVE-2022-31769MEDIUM5.3IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration i...
CVE-2022-30611MEDIUM5.4IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper val...
CVE-2022-30610MEDIUM4.5IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a pa...
CVE-2022-22479HIGH8.8IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now