2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-23037HIGH7Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t...
CVE-2022-23036HIGH7Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t...
CVE-2022-26847MEDIUM5.3SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.
CVE-2022-26846HIGH8.8SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code.
CVE-2022-26778MEDIUM6.5Veritas System Recovery (VSR) 18 and 21 stores a network destination password in the Windows registry during configurati...
CVE-2022-26662HIGH7.5An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x throu...
CVE-2022-26661MEDIUM6.5An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x an...
CVE-2022-26652MEDIUM6.5NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStre...
CVE-2022-26521HIGH7.2Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable...
CVE-2022-26520CRITICAL9.8In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to...
CVE-2022-26488HIGH7In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The...
CVE-2022-26355MEDIUM4.4Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a regist...
CVE-2022-26333Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2022-26311HIGH7.5Couchbase Operator 2.2.x before 2.2.3 exposes Sensitive Information to an Unauthorized Actor. Secrets are not redacted i...
CVE-2022-26143CRITICAL9.8The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows...
CVE-2022-26131CRITICAL9.8Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals.
CVE-2022-26104MEDIUM5.3SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messag...
CVE-2022-26103MEDIUM5.3Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access inf...
CVE-2022-26102MEDIUM5.4Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an a...
CVE-2022-26101MEDIUM6.1Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site S...
CVE-2022-26100CRITICAL9.8SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR proce...
CVE-2022-25922CRITICAL9.1Power Line Communications PLC4TRUCKS J2497 trailer brake controllers implement diagnostic functions which can be invoked...
CVE-2022-25830LOW3.3Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access pa...
CVE-2022-25829LOW3.3Information Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access pa...
CVE-2022-25828LOW3.3Information Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access pas...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now