2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24930 | LOW | 3.3 | 0.4% | Mar 10, 2022 | An Improper access control vulnerability in StRetailModeReceiver in Wear OS 3.0 prior to Firmware update MAR-2022 Releas... |
| CVE-2022-24929 | LOW | 3.3 | 0.1% | Mar 10, 2022 | Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without... |
| CVE-2022-24928 | HIGH | 7.8 | 0.1% | Mar 10, 2022 | Security misconfiguration of RKP in kernel prior to SMR Mar-2022 Release 1 allows a system not to be protected by RKP. |
| CVE-2022-24915 | HIGH | 8.8 | 1.0% | Mar 10, 2022 | The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to in... |
| CVE-2022-24652 | CRITICAL | 9.8 | 2.5% | Mar 10, 2022 | sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, res... |
| CVE-2022-24651 | CRITICAL | 9.8 | 2.5% | Mar 10, 2022 | sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, res... |
| CVE-2022-24644 | HIGH | 8.8 | 2.2% | Mar 10, 2022 | ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated u... |
| CVE-2022-24618 | HIGH | 7.8 | 0.2% | Mar 10, 2022 | Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unpr... |
| CVE-2022-24609 | CRITICAL | 9.8 | 1.5% | Mar 10, 2022 | Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an a... |
| CVE-2022-24608 | MEDIUM | 6.1 | 0.7% | Mar 10, 2022 | Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php. |
| CVE-2022-24607 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php. |
| CVE-2022-24606 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php. |
| CVE-2022-24605 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php. |
| CVE-2022-24604 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php. |
| CVE-2022-24603 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php. |
| CVE-2022-24602 | CRITICAL | 9.8 | 1.1% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php. |
| CVE-2022-24601 | HIGH | 7.5 | 1.1% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information t... |
| CVE-2022-24600 | CRITICAL | 9.8 | 1.3% | Mar 10, 2022 | Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL ... |
| CVE-2022-24432 | MEDIUM | 5.4 | 0.6% | Mar 10, 2022 | Persistent cross-site scripting (XSS) in the web interface of ipDIO allows an authenticated remote attacker to introduce... |
| CVE-2022-24399 | MEDIUM | 6.1 | 1.4% | Mar 10, 2022 | The SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not sufficiently sanitize the input na... |
| CVE-2022-24398 | MEDIUM | 6.5 | 0.8% | Mar 10, 2022 | Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticate... |
| CVE-2022-24397 | MEDIUM | 6.1 | 0.8% | Mar 10, 2022 | SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, ... |
| CVE-2022-24396 | HIGH | 7.8 | 0.5% | Mar 10, 2022 | The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functiona... |
| CVE-2022-24395 | MEDIUM | 6.1 | 0.6% | Mar 10, 2022 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-c... |
| CVE-2022-24286 | HIGH | 7.8 | 0.2% | Mar 10, 2022 | Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnera... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now