2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-48256HIGH7.5Technitium DNS Server before 10.0 allows a self-CNAME denial-of-service attack in which a CNAME loop causes an answer to...
CVE-2022-42275HIGH7.1NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. Th...
CVE-2022-42274HIGH7.8NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause ...
CVE-2022-3161HIGH7.8 The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF files. This could allow ...
CVE-2022-3160HIGH7.8 The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted ...
CVE-2022-3159HIGH7.8The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially craf...
CVE-2022-46463HIGH7.5An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories with...
CVE-2022-41778HIGH8.8 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through...
CVE-2022-42273HIGH8.8NVIDIA BMC contains a vulnerability in libwebsocket, where an authorized attacker can cause a buffer overflow and cause ...
CVE-2022-42272HIGH8.8NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow, which may...
CVE-2022-25027HIGH7.5The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authenticatio...
CVE-2022-25026HIGH7.5A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensi...
CVE-2022-46623HIGH7.8Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter.
CVE-2022-46472HIGH7.2Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /hss/cla...
CVE-2022-4743HIGH7.5A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerab...
CVE-2022-3977HIGH7.8A use-after-free flaw was found in the Linux kernel MCTP (Management Component Transport Protocol) functionality. This i...
CVE-2022-43591HIGH8.8A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javas...
CVE-2022-40983HIGH8.8An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted jav...
CVE-2022-46372HIGH8.8Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow ...
CVE-2022-46370HIGH7.5Rumpus - FTP server version 9.0.7.1 Improper Token Verification– vulnerability may allow bypassing identity verification...
CVE-2022-46368HIGH8.8Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on b...
CVE-2022-46367HIGH8.8Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege esca...
CVE-2022-39182HIGH8.8H C Mingham-Smith Ltd - Tardis 2000 Privilege escalation.Version 1.6 is vulnerable to privilege escalation which may all...
CVE-2022-2155HIGH7.1 A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access contro...
CVE-2022-4167HIGH7.5Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now