2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24967MEDIUM5.4Black Rainbow NIMBUS before 3.7.0 allows stored Cross-site Scripting (XSS).
CVE-2022-24702CRITICAL9.8An issue was discovered in WinAPRS 2.9.0. A buffer overflow in the VHF KISS TNC component allows a remote attacker to ac...
CVE-2022-24701HIGH7.8An issue was discovered in WinAPRS 2.9.0. A buffer overflow in national.txt processing allows a local attacker to cause ...
CVE-2022-24700HIGH7.5An issue was discovered in WinAPRS 2.9.0. A buffer overflow in DIGI address processing for VHF KISS packets allows a rem...
CVE-2022-24581HIGH7.5ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an exte...
CVE-2022-24241HIGH7.5ACEweb Online Portal 3.5.065 was discovered to contain an External Controlled File Path and Name vulnerability via the t...
CVE-2022-24240CRITICAL9.8ACEweb Online Portal 3.5.065 was discovered to contain a SQL injection vulnerability via the criteria parameter in shows...
CVE-2022-24239CRITICAL9.8ACEweb Online Portal 3.5.065 was discovered to contain an unrestricted file upload vulnerability via attachments.awp.
CVE-2022-24238MEDIUM6.1ACEweb Online Portal 3.5.065 was discovered to contain a cross-site scripting (XSS) vulnerability via the txtNmName1 par...
CVE-2022-23237MEDIUM6.1E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks...
CVE-2022-23236MEDIUM4.4E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext with...
CVE-2022-22767HIGH8.8Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentia...
CVE-2022-1968HIGH7.8Use After Free in GitHub repository vim/vim prior to 8.2.
CVE-2022-1949HIGH7.5An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect r...
CVE-2022-1943HIGH7.8A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers s...
CVE-2022-1929HIGH7.5An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacke...
CVE-2022-1797HIGH8.6A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition ...
CVE-2022-1789MEDIUM6.8With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed wit...
CVE-2022-1786HIGH7.8A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SE...
CVE-2022-1661HIGH7.5The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating s...
CVE-2022-1660CRITICAL9.8The affected products are vulnerable of untrusted data due to deserialization without prior authorization/authentication...
CVE-2022-1652HIGH7.8Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-fre...
CVE-2022-1462MEDIUM6.3An out-of-bounds read flaw was found in the Linux kernel’s TeleTYpe subsystem. The issue occurs in how a user triggers a...
CVE-2022-1419HIGH7.8The root cause of this vulnerability is that the ioctl$DRM_IOCTL_MODE_DESTROY_DUMB can decrease refcount of *drm_vgem_ge...
CVE-2022-1215HIGH7.8A format string vulnerability was found in libinput

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now