2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29967 | HIGH | 7.5 | 1.5% | Apr 29, 2022 | static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal. |
| CVE-2022-29947 | MEDIUM | 6.1 | 0.6% | Apr 29, 2022 | Woodpecker before 0.15.1 allows XSS via build logs because web/src/components/repo/build/BuildLog.vue lacks escaping. |
| CVE-2022-28198 | MEDIUM | 6.8 | 0.3% | Apr 29, 2022 | NVIDIA Omniverse Nucleus and Cache contain a vulnerability in its configuration of OpenSSL, where an attacker with physi... |
| CVE-2022-29945 | HIGH | 7.5 | 0.7% | Apr 29, 2022 | DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical locati... |
| CVE-2022-25854 | MEDIUM | 5.4 | 0.9% | Apr 29, 2022 | This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input o... |
| CVE-2022-1543 | HIGH | 8.8 | 1.1% | Apr 29, 2022 | Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large e... |
| CVE-2022-29937 | HIGH | 8.8 | 1.5% | Apr 29, 2022 | USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because som... |
| CVE-2022-29936 | HIGH | 8.8 | 2.0% | Apr 29, 2022 | USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/q... |
| CVE-2022-29935 | HIGH | 7.5 | 1.1% | Apr 29, 2022 | USU Oracle Optimization before 5.17.5 allows attackers to discover the quantum credentials via an agent-installer downlo... |
| CVE-2022-29934 | HIGH | 7.8 | 0.3% | Apr 29, 2022 | USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root acc... |
| CVE-2022-29451 | HIGH | 8.8 | 0.6% | Apr 29, 2022 | Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <=... |
| CVE-2022-29414 | MEDIUM | 5.4 | 0.4% | Apr 29, 2022 | Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 21... |
| CVE-2022-28994 | CRITICAL | 9.8 | 2.2% | Apr 29, 2022 | Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request. |
| CVE-2022-28480 | CRITICAL | 9.8 | 1.7% | Apr 29, 2022 | ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe. |
| CVE-2022-1403 | HIGH | 7.8 | 0.8% | Apr 29, 2022 | ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing... |
| CVE-2022-1402 | HIGH | 7.1 | 0.8% | Apr 29, 2022 | ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing... |
| CVE-2022-0984 | MEDIUM | 4.3 | 0.5% | Apr 29, 2022 | Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course b... |
| CVE-2022-29856 | HIGH | 7.5 | 1.5% | Apr 29, 2022 | A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages. |
| CVE-2022-1353 | HIGH | 7.1 | 0.4% | Apr 29, 2022 | A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a loc... |
| CVE-2022-1249 | LOW | 3.3 | 0.2% | Apr 29, 2022 | A NULL pointer dereference flaw was found in pesign's cms_set_pw_data() function of the cms_common.c file. The function ... |
| CVE-2022-1227 | HIGH | 8.8 | 4.2% | Apr 29, 2022 | A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public r... |
| CVE-2022-1195 | MEDIUM | 5.5 | 0.2% | Apr 29, 2022 | A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker ... |
| CVE-2022-1114 | HIGH | 7.1 | 1.1% | Apr 29, 2022 | A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is ... |
| CVE-2022-1048 | HIGH | 7 | 0.2% | Apr 29, 2022 | A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM... |
| CVE-2022-1015 | MEDIUM | 6.6 | 1.5% | Apr 29, 2022 | A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now