2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29967HIGH7.5static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal.
CVE-2022-29947MEDIUM6.1Woodpecker before 0.15.1 allows XSS via build logs because web/src/components/repo/build/BuildLog.vue lacks escaping.
CVE-2022-28198MEDIUM6.8NVIDIA Omniverse Nucleus and Cache contain a vulnerability in its configuration of OpenSSL, where an attacker with physi...
CVE-2022-29945HIGH7.5DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical locati...
CVE-2022-25854MEDIUM5.4This affects the package @yaireo/tagify before 4.9.8. The package is used for rendering UI components inside the input o...
CVE-2022-1543HIGH8.8Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large e...
CVE-2022-29937HIGH8.8USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because som...
CVE-2022-29936HIGH8.8USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/q...
CVE-2022-29935HIGH7.5USU Oracle Optimization before 5.17.5 allows attackers to discover the quantum credentials via an agent-installer downlo...
CVE-2022-29934HIGH7.8USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root acc...
CVE-2022-29451HIGH8.8Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <=...
CVE-2022-29414MEDIUM5.4Multiple (13x) Cross-Site Request Forgery (CSRF) vulnerabilities in WPKube's Subscribe To Comments Reloaded plugin <= 21...
CVE-2022-28994CRITICAL9.8Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request.
CVE-2022-28480CRITICAL9.8ALLMediaServer 1.6 is vulnerable to Buffer Overflow via MediaServer.exe.
CVE-2022-1403HIGH7.8ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing...
CVE-2022-1402HIGH7.1ASDA-Soft: Version 5.4.1.0 and prior does not properly sanitize input while processing a specific project file, allowing...
CVE-2022-0984MEDIUM4.3Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course b...
CVE-2022-29856HIGH7.5A hardcoded cryptographic key in Automation360 22 allows an attacker to decrypt exported RPA packages.
CVE-2022-1353HIGH7.1A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a loc...
CVE-2022-1249LOW3.3A NULL pointer dereference flaw was found in pesign's cms_set_pw_data() function of the cms_common.c file. The function ...
CVE-2022-1227HIGH8.8A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public r...
CVE-2022-1195MEDIUM5.5A use-after-free vulnerability was found in the Linux kernel in drivers/net/hamradio. This flaw allows a local attacker ...
CVE-2022-1114HIGH7.1A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is ...
CVE-2022-1048HIGH7A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM...
CVE-2022-1015MEDIUM6.6A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now