2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22145HIGH8.1CAMS for HIS Log Server contained in the following Yokogawa Electric products is vulnerable to uncontrolled resource con...
CVE-2022-22141HIGH7.8'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe...
CVE-2022-21808HIGH8.8Path traversal vulnerability exists in CAMS for HIS Server contained in the following Yokogawa Electric products: CENTUM...
CVE-2022-21194CRITICAL9.8The following Yokogawa Electric products do not change the passwords of the internal Windows accounts from the initial c...
CVE-2022-21177HIGH8.1There is a path traversal vulnerability in CAMS for HIS Log Server contained in the following Yokogawa Electric products...
CVE-2022-26878MEDIUM5.5drivers/bluetooth/virtio_bt.c in the Linux kernel before 5.16.3 has a memory leak (socket buffers have memory allocated ...
CVE-2022-26874MEDIUM5.4lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to accoun...
CVE-2022-0822MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.
CVE-2022-25512HIGH7.5FreeTAKServer-UI v1.9.8 was discovered to leak sensitive API and Websocket keys.
CVE-2022-25511MEDIUM6.5An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place ...
CVE-2022-25510HIGH8.8FreeTAKServer 1.9.8 contains a hardcoded Flask secret key which allows attackers to create crafted cookies to bypass aut...
CVE-2022-25508HIGH7.5An access control issue in the component /ManageRoute/postRoute of FreeTAKServer v1.9.8 allows unauthenticated attackers...
CVE-2022-25507MEDIUM5.4FreeTAKServer-UI v1.9.8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Callsign par...
CVE-2022-25506MEDIUM6.5FreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser.
CVE-2022-0821MEDIUM6.5Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.
CVE-2022-0820MEDIUM6.1Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0.
CVE-2022-0815HIGH7.3Improper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a ...
CVE-2022-0280HIGH7A race condition vulnerability exists in the QuickClean feature of McAfee Total Protection for Windows prior to 16.0.43 ...
CVE-2022-24750HIGH7.8UltraVNC is a free and open source remote pc access software. A vulnerability has been found in versions prior to 1.3.8....
CVE-2022-24726HIGH7.5Istio is an open platform to connect, manage, and secure microservices. In affected versions the Istio control plane, is...
CVE-2022-23042HIGH7Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t...
CVE-2022-23041HIGH7Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t...
CVE-2022-23040HIGH7Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t...
CVE-2022-23039HIGH7Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t...
CVE-2022-23038HIGH7Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now