CVE Vulnerabilities in 2022

111 documented vulnerabilities published in 2022.

Other years: 2026 2025 2024 2023 2021 2020

Top Affected Vendors in 2022

All CVEs from 2022

CVE-2022-3775
7.1 high

When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2's heap, leading to memory corruption and a

Gnu Grub2 Dec 19, 2022
CVE-2022-47549
6.4 medium

An unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TEE) before 3.20 allows a physically proximate adversary to bypass signature verification and install malicious trusted applications via electromagnetic fault injections.

Trustedfirmware Op-Tee Dec 19, 2022
CVE-2022-46393
9.8 critical

An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.

Arm Mbed Tls Dec 15, 2022
CVE-2022-46392
5.3 medium

An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single pri

Arm Mbed Tls Dec 15, 2022
CVE-2022-2601
8.6 high

A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker

Gnu Grub2 Dec 14, 2022
CVE-2022-44702
7.8 high

Windows Terminal Remote Code Execution Vulnerability

Microsoft Terminal Dec 13, 2022
CVE-2022-44696
7.8 high

Microsoft Office Visio Remote Code Execution Vulnerability

Microsoft 365 Apps Dec 13, 2022
CVE-2022-44695
7.8 high

Microsoft Office Visio Remote Code Execution Vulnerability

Microsoft 365 Apps Dec 13, 2022
CVE-2022-44694
7.8 high

Microsoft Office Visio Remote Code Execution Vulnerability

Microsoft 365 Apps Dec 13, 2022
CVE-2022-3907
7.5 high

The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API keys against the ones stored in the site options.

Clerk.Io Clerk.Io Dec 5, 2022
CVE-2022-2808
8.8 high

Authorization Bypass Through User-Controlled Key vulnerability in Algan Software Prens Student Information System allows Object Relational Mapping Injection. This issue affects Prens Student Information System: before 2.1.11.

Algan Prens Student Information System Dec 2, 2022
CVE-2022-2807
9.8 critical

SQL Injection vulnerability in Algan Software Prens Student Information System allows SQL Injection. This issue affects Prens Student Information System: before 2.1.11.

Algan Prens Student Information System Dec 2, 2022
CVE-2022-46152
8.2 high

OP-TEE Trusted OS is the secure side implementation of OP-TEE project, a Trusted Execution Environment. Versions prior to 3.19.0, contain an Improper Validation of Array Index vulnerability. The function `cleanup_shm_refs()` is called by both `entry_invoke_command()` and `entry_open_session()`. The

Trustedfirmware Op-Tee Nov 29, 2022
CVE-2022-24038
6.5 medium

Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to damage the page where the agents are listed.

Karmasis Infraskope Siem\+ Nov 18, 2022
CVE-2022-24037
8.2 high

Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to obtain critical information.

Karmasis Infraskope Siem\+ Nov 18, 2022
CVE-2022-24036
8.6 high

Karmasis Informatics Infraskope SIEM+ has an unauthenticated access vulnerability which could allow an unauthenticated attacker to modificate logs.

Karmasis Infraskope Siem\+ Nov 16, 2022
CVE-2022-41107
7.8 high

Microsoft Office Graphics Remote Code Execution Vulnerability

Microsoft 365 Apps Nov 9, 2022
CVE-2022-41106
8.8 high

Microsoft Excel Remote Code Execution Vulnerability

Microsoft 365 Apps Nov 9, 2022
CVE-2022-41105
5.5 medium

Microsoft Excel Information Disclosure Vulnerability

Microsoft 365 Apps Nov 9, 2022
CVE-2022-41104
5.5 medium

Microsoft Excel Security Feature Bypass Vulnerability

Microsoft 365 Apps Nov 9, 2022
CVE-2022-41103
5.5 medium

Microsoft Word Information Disclosure Vulnerability

Microsoft 365 Apps Nov 9, 2022
CVE-2022-41063
7.8 high

Microsoft Excel Remote Code Execution Vulnerability

Microsoft 365 Apps Nov 9, 2022
CVE-2022-41061
7.8 high

Microsoft Word Remote Code Execution Vulnerability

Microsoft 365 Apps Nov 9, 2022
CVE-2022-41060
5.5 medium

Microsoft Word Information Disclosure Vulnerability

Microsoft 365 Apps Nov 9, 2022