2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22187HIGH7.8An Improper Privilege Management vulnerability in the Windows Installer framework used in the Juniper Networks Juniper I...
CVE-2022-22186MEDIUM6.5Due to an Improper Initialization vulnerability in Juniper Networks Junos OS on EX4650 devices, packets received on the ...
CVE-2022-22185HIGH7.5A vulnerability in Juniper Networks Junos OS on SRX Series, allows a network-based unauthenticated attacker to cause a D...
CVE-2022-22183HIGH7.5An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated att...
CVE-2022-22182MEDIUM6.1A Cross-site Scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web allows an attacker to construct a URL that...
CVE-2022-22181MEDIUM5.4A reflected Cross-site Scripting (XSS) vulnerability in J-Web of Juniper Networks Junos OS allows a network-based authen...
CVE-2022-27008HIGH7.5nginx njs 0.7.2 is vulnerable to Buffer Overflow. Type confused in Array.prototype.concat() when a slow array appended e...
CVE-2022-27007CRITICAL9.8nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a resto...
CVE-2022-1258HIGH7.2A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be exploited by...
CVE-2022-1257MEDIUM5.5Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a loca...
CVE-2022-1256HIGH7.8A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain s...
CVE-2022-27458Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-27447. Reason: This candidate is a reservation d...
CVE-2022-27457HIGH7.5MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_mb_wc_latin1 at /string...
CVE-2022-27456HIGH7.5MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component VDec::VDec at /sql/sql_typ...
CVE-2022-27455HIGH7.5MariaDB Server v10.6.3 and below was discovered to contain an use-after-free in the component my_wildcmp_8bit_impl at /s...
CVE-2022-27452HIGH7.5MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.cc.
CVE-2022-27451HIGH7.5MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/field_conv.cc.
CVE-2022-27449HIGH7.5MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_func.cc:148.
CVE-2022-27448HIGH7.5There is an Assertion failure in MariaDB Server v10.9 and below via 'node->pcur->rel_pos == BTR_PCUR_ON' at /row/row0mys...
CVE-2022-27447HIGH7.5MariaDB Server v10.9 and below was discovered to contain a use-after-free via the component Binary_string::free_buffer()...
CVE-2022-27446HIGH7.5MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_cmpfunc.h.
CVE-2022-27445HIGH7.5MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/sql_window.cc.
CVE-2022-27444HIGH7.5MariaDB Server v10.9 and below was discovered to contain a segmentation fault via the component sql/item_subselect.cc.
CVE-2022-26507CRITICAL9.8A heap-based buffer overflow exists in XML Decompression DecodeTreeBlock in AT&T Labs Xmill 0.7. A crafted input file ca...
CVE-2022-1351MEDIUM5.4Stored XSS in Tooltip in GitHub repository pimcore/pimcore prior to 10.4.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now