2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2013 | HIGH | 7.5 | 0.8% | Jun 13, 2022 | In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental f... |
| CVE-2022-2054 | HIGH | 7.8 | 0.5% | Jun 12, 2022 | Code Injection in GitHub repository nuitka/nuitka prior to 0.9. |
| CVE-2022-30780 | HIGH | 7.5 | 56.4% | Jun 11, 2022 | Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connect... |
| CVE-2022-32981 | HIGH | 7.8 | 1.0% | Jun 10, 2022 | An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in pt... |
| CVE-2022-29095 | CRITICAL | 9.6 | 1.1% | Jun 10, 2022 | Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 ... |
| CVE-2022-29094 | HIGH | 7.1 | 0.2% | Jun 10, 2022 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial version... |
| CVE-2022-29093 | HIGH | 7.1 | 0.2% | Jun 10, 2022 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial version... |
| CVE-2022-29092 | HIGH | 7.8 | 0.4% | Jun 10, 2022 | Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial version... |
| CVE-2022-25863 | CRITICAL | 9.8 | 1.8% | Jun 10, 2022 | The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted... |
| CVE-2022-25851 | HIGH | 7.5 | 1.8% | Jun 10, 2022 | The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause ... |
| CVE-2022-25845 | CRITICAL | 9.8 | 17.8% | Jun 10, 2022 | The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the defa... |
| CVE-2022-24429 | HIGH | 7.8 | 0.8% | Jun 10, 2022 | The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG ... |
| CVE-2022-24376 | CRITICAL | 9.8 | 3.0% | Jun 10, 2022 | All versions of package git-promise are vulnerable to Command Injection due to an inappropriate fix of a prior [vulnerab... |
| CVE-2022-24278 | CRITICAL | 9.8 | 2.0% | Jun 10, 2022 | The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags... |
| CVE-2022-21211 | HIGH | 7.5 | 0.9% | Jun 10, 2022 | This affects all versions of package posix. When invoking the toString method, it will fallback to 0x0 value, as the val... |
| CVE-2022-2042 | HIGH | 7.8 | 1.4% | Jun 10, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-31287 | MEDIUM | 5.5 | 0.6% | Jun 10, 2022 | An issue was discovered in Bento4 v1.2. There is an allocation size request error in /Ap4RtpAtom.cpp. |
| CVE-2022-31285 | MEDIUM | 5.5 | 0.6% | Jun 10, 2022 | An issue was discovered in Bento4 1.2. The allocator is out of memory in /Source/C++/Core/Ap4Array.h. |
| CVE-2022-31282 | MEDIUM | 5.5 | 0.6% | Jun 10, 2022 | Bento4 MP4Dump v1.2 was discovered to contain a segmentation violation via an unknown address at /Source/C++/Core/Ap4Dat... |
| CVE-2022-31402 | MEDIUM | 6.1 | 2.1% | Jun 10, 2022 | ITOP v3.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via /itop/webservices/export-v2.php. |
| CVE-2022-29948 | MEDIUM | 4.6 | 0.5% | Jun 10, 2022 | Due to an insecure design, the Lepin EP-KP001 flash drive through KP001_V19 is vulnerable to an authentication bypass at... |
| CVE-2022-31769 | MEDIUM | 5.3 | 1.1% | Jun 10, 2022 | IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 could allow a remote attacker to view product configuration i... |
| CVE-2022-30611 | MEDIUM | 5.4 | 0.6% | Jun 10, 2022 | IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper val... |
| CVE-2022-30610 | MEDIUM | 4.5 | 0.5% | Jun 10, 2022 | IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a pa... |
| CVE-2022-22479 | HIGH | 8.8 | 0.3% | Jun 10, 2022 | IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now