2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-30976HIGH7.1GPAC 2.0.0 misuses a certain Unicode utf8_wcslen (renamed gf_utf8_wcslen) function in utils/utf.c, resulting in a heap-b...
CVE-2022-30975MEDIUM5.5In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp.
CVE-2022-30974MEDIUM5.5compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a differe...
CVE-2022-29174HIGH8.1countly-server is the server-side part of Countly, a product analytics solution. Prior to versions 22.03.7 and 21.11.4, ...
CVE-2022-29162HIGH7.8runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in r...
CVE-2022-28616CRITICAL9.8A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE ha...
CVE-2022-1362HIGH7.3The affected On-Premise cnMaestro is vulnerable inside a specific route where a user can upload a crafted package to the...
CVE-2022-1361HIGH7.5The affected On-Premise cnMaestro is vulnerable to a pre-auth data exfiltration through improper neutralization of speci...
CVE-2022-1360CRITICAL9.8The affected On-Premise cnMaestro is vulnerable to execution of code on the cnMaestro hosting server. This could allow a...
CVE-2022-1359HIGH7.5The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to ...
CVE-2022-1358HIGH7.5The affected On-Premise is vulnerable to data exfiltration through improper neutralization of special elements used in a...
CVE-2022-1357CRITICAL9.8The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrar...
CVE-2022-1356HIGH7.8cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a us...
CVE-2022-30054CRITICAL9.8In Covid 19 Travel Pass Management 1.0, the code parameter is vulnerable to SQL injection attacks.
CVE-2022-30053CRITICAL9.8In Toll Tax Management System 1.0, the id parameter appears to be vulnerable to SQL injection attacks.
CVE-2022-30052CRITICAL9.8In Home Clean Service System 1.0, the password parameter is vulnerable to SQL injection attacks.
CVE-2022-30045MEDIUM6.5An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs incorrect memory handling whi...
CVE-2022-29436MEDIUM6.1Persistent Cross-Site Scripting (XSS) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on Wo...
CVE-2022-29435MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Alexander Stokmann's Code Snippets Extended plugin <= 1.4.7 on WordPr...
CVE-2022-28617CRITICAL9.8A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has prov...
CVE-2022-28192MEDIUM4.1NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-f...
CVE-2022-28191MEDIUM5.5NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consum...
CVE-2022-28190MEDIUM5.5NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkD...
CVE-2022-28189MEDIUM5.5NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkD...
CVE-2022-28188MEDIUM5.5NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkD...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now