2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23037 | HIGH | 7 | 0.3% | Mar 10, 2022 | Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t... |
| CVE-2022-23036 | HIGH | 7 | 0.4% | Mar 10, 2022 | Linux PV device frontends vulnerable to attacks by backends T[his CNA information record relates to multiple CVEs; the t... |
| CVE-2022-26847 | MEDIUM | 5.3 | 1.3% | Mar 10, 2022 | SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects. |
| CVE-2022-26846 | HIGH | 8.8 | 2.9% | Mar 10, 2022 | SPIP before 3.2.14 and 4.x before 4.0.5 allows remote authenticated editors to execute arbitrary code. |
| CVE-2022-26778 | MEDIUM | 6.5 | 0.4% | Mar 10, 2022 | Veritas System Recovery (VSR) 18 and 21 stores a network destination password in the Windows registry during configurati... |
| CVE-2022-26662 | HIGH | 7.5 | 1.9% | Mar 10, 2022 | An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x throu... |
| CVE-2022-26661 | MEDIUM | 6.5 | 1.4% | Mar 10, 2022 | An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x an... |
| CVE-2022-26652 | MEDIUM | 6.5 | 2.3% | Mar 10, 2022 | NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStre... |
| CVE-2022-26521 | HIGH | 7.2 | 9.5% | Mar 10, 2022 | Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable... |
| CVE-2022-26520 | CRITICAL | 9.8 | 2.9% | Mar 10, 2022 | In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to... |
| CVE-2022-26488 | HIGH | 7 | 1.4% | Mar 10, 2022 | In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The... |
| CVE-2022-26355 | MEDIUM | 4.4 | 0.2% | Mar 10, 2022 | Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a regist... |
| CVE-2022-26333 | — | — | — | Mar 10, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2022-26311 | HIGH | 7.5 | 1.1% | Mar 10, 2022 | Couchbase Operator 2.2.x before 2.2.3 exposes Sensitive Information to an Unauthorized Actor. Secrets are not redacted i... |
| CVE-2022-26143 | CRITICAL | 9.8 | 87.6% | Mar 10, 2022 | The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows... |
| CVE-2022-26131 | CRITICAL | 9.8 | 1.3% | Mar 10, 2022 | Power Line Communications PLC4TRUCKS J2497 trailer receivers are susceptible to remote RF induced signals. |
| CVE-2022-26104 | MEDIUM | 5.3 | 0.7% | Mar 10, 2022 | SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messag... |
| CVE-2022-26103 | MEDIUM | 5.3 | 0.7% | Mar 10, 2022 | Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access inf... |
| CVE-2022-26102 | MEDIUM | 5.4 | 0.5% | Mar 10, 2022 | Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an a... |
| CVE-2022-26101 | MEDIUM | 6.1 | 1.4% | Mar 10, 2022 | Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site S... |
| CVE-2022-26100 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a result, the SAPCAR proce... |
| CVE-2022-25922 | CRITICAL | 9.1 | 1.1% | Mar 10, 2022 | Power Line Communications PLC4TRUCKS J2497 trailer brake controllers implement diagnostic functions which can be invoked... |
| CVE-2022-25830 | LOW | 3.3 | 0.2% | Mar 10, 2022 | Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access pa... |
| CVE-2022-25829 | LOW | 3.3 | 0.2% | Mar 10, 2022 | Information Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access pa... |
| CVE-2022-25828 | LOW | 3.3 | 0.2% | Mar 10, 2022 | Information Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access pas... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now