2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24930LOW3.3An Improper access control vulnerability in StRetailModeReceiver in Wear OS 3.0 prior to Firmware update MAR-2022 Releas...
CVE-2022-24929LOW3.3Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without...
CVE-2022-24928HIGH7.8Security misconfiguration of RKP in kernel prior to SMR Mar-2022 Release 1 allows a system not to be protected by RKP.
CVE-2022-24915HIGH8.8The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to in...
CVE-2022-24652CRITICAL9.8sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, res...
CVE-2022-24651CRITICAL9.8sentcms 4.0.x allows remote attackers to cause arbitrary file uploads through an unauthorized file upload interface, res...
CVE-2022-24644HIGH8.8ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability during an unauthenticated u...
CVE-2022-24618HIGH7.8Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unpr...
CVE-2022-24609CRITICAL9.8Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an a...
CVE-2022-24608MEDIUM6.1Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.
CVE-2022-24607CRITICAL9.8Luocms v2.0 is affected by SQL Injection in /admin/news/news_ok.php.
CVE-2022-24606CRITICAL9.8Luocms v2.0 is affected by SQL Injection in /admin/news/sort_ok.php.
CVE-2022-24605CRITICAL9.8Luocms v2.0 is affected by SQL Injection in /admin/link/link_ok.php.
CVE-2022-24604CRITICAL9.8Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.
CVE-2022-24603CRITICAL9.8Luocms v2.0 is affected by SQL Injection in /admin/news/sort_mod.php.
CVE-2022-24602CRITICAL9.8Luocms v2.0 is affected by SQL Injection in /admin/news/news_mod.php.
CVE-2022-24601HIGH7.5Luocms v2.0 is affected by SQL Injection in /admin/manager/admin_mod.php. An attacker can obtain sensitive information t...
CVE-2022-24600CRITICAL9.8Luocms v2.0 is affected by SQL Injection through /admin/login.php. An attacker can log in to the background through SQL ...
CVE-2022-24432MEDIUM5.4Persistent cross-site scripting (XSS) in the web interface of ipDIO allows an authenticated remote attacker to introduce...
CVE-2022-24399MEDIUM6.1The SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not sufficiently sanitize the input na...
CVE-2022-24398MEDIUM6.5Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticate...
CVE-2022-24397MEDIUM6.1SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, ...
CVE-2022-24396HIGH7.8The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functiona...
CVE-2022-24395MEDIUM6.1SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-c...
CVE-2022-24286HIGH7.8Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnera...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now