2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-48256 | HIGH | 7.5 | 0.7% | Jan 13, 2023 | Technitium DNS Server before 10.0 allows a self-CNAME denial-of-service attack in which a CNAME loop causes an answer to... |
| CVE-2022-42275 | HIGH | 7.1 | 0.2% | Jan 13, 2023 | NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. Th... |
| CVE-2022-42274 | HIGH | 7.8 | 0.3% | Jan 13, 2023 | NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause ... |
| CVE-2022-3161 | HIGH | 7.8 | 0.4% | Jan 13, 2023 | The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF files. This could allow ... |
| CVE-2022-3160 | HIGH | 7.8 | 0.4% | Jan 13, 2023 | The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted ... |
| CVE-2022-3159 | HIGH | 7.8 | 0.5% | Jan 13, 2023 | The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially craf... |
| CVE-2022-46463 | HIGH | 7.5 | 6.2% | Jan 13, 2023 | An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories with... |
| CVE-2022-41778 | HIGH | 8.8 | 1.0% | Jan 13, 2023 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through... |
| CVE-2022-42273 | HIGH | 8.8 | 0.8% | Jan 12, 2023 | NVIDIA BMC contains a vulnerability in libwebsocket, where an authorized attacker can cause a buffer overflow and cause ... |
| CVE-2022-42272 | HIGH | 8.8 | 0.8% | Jan 12, 2023 | NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow, which may... |
| CVE-2022-25027 | HIGH | 7.5 | 1.0% | Jan 12, 2023 | The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authenticatio... |
| CVE-2022-25026 | HIGH | 7.5 | 24.2% | Jan 12, 2023 | A Server-Side Request Forgery (SSRF) in Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to gain access to sensi... |
| CVE-2022-46623 | HIGH | 7.8 | 0.4% | Jan 12, 2023 | Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter. |
| CVE-2022-46472 | HIGH | 7.2 | 0.7% | Jan 12, 2023 | Helmet Store Showroom Site v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /hss/cla... |
| CVE-2022-4743 | HIGH | 7.5 | 1.3% | Jan 12, 2023 | A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerab... |
| CVE-2022-3977 | HIGH | 7.8 | 0.3% | Jan 12, 2023 | A use-after-free flaw was found in the Linux kernel MCTP (Management Component Transport Protocol) functionality. This i... |
| CVE-2022-43591 | HIGH | 8.8 | 1.1% | Jan 12, 2023 | A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javas... |
| CVE-2022-40983 | HIGH | 8.8 | 1.1% | Jan 12, 2023 | An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted jav... |
| CVE-2022-46372 | HIGH | 8.8 | 0.9% | Jan 12, 2023 | Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow ... |
| CVE-2022-46370 | HIGH | 7.5 | 0.2% | Jan 12, 2023 | Rumpus - FTP server version 9.0.7.1 Improper Token Verification– vulnerability may allow bypassing identity verification... |
| CVE-2022-46368 | HIGH | 8.8 | 0.3% | Jan 12, 2023 | Rumpus - FTP server version 9.0.7.1 Cross-site request forgery (CSRF) – vulnerability may allow unauthorized action on b... |
| CVE-2022-46367 | HIGH | 8.8 | 0.3% | Jan 12, 2023 | Rumpus - FTP server Cross-site request forgery (CSRF) – Privilege escalation vulnerability that may allow privilege esca... |
| CVE-2022-39182 | HIGH | 8.8 | 0.3% | Jan 12, 2023 | H C Mingham-Smith Ltd - Tardis 2000 Privilege escalation.Version 1.6 is vulnerable to privilege escalation which may all... |
| CVE-2022-2155 | HIGH | 7.1 | 0.4% | Jan 12, 2023 | A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access contro... |
| CVE-2022-4167 | HIGH | 7.5 | 0.5% | Jan 12, 2023 | Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now