2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22546 | MEDIUM | 5.4 | 0.5% | Feb 9, 2022 | Due to improper HTML encoding in input control summary, an authorized attacker can execute XSS vulnerability in SAP Busi... |
| CVE-2022-22545 | MEDIUM | 4.9 | 0.8% | Feb 9, 2022 | A high privileged user who has access to transaction SM59 can read connection details stored with the destination for ht... |
| CVE-2022-22544 | CRITICAL | 9.1 | 1.3% | Feb 9, 2022 | Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all c... |
| CVE-2022-22543 | HIGH | 7.5 | 1.3% | Feb 9, 2022 | SAP NetWeaver Application Server for ABAP (Kernel) and ABAP Platform (Kernel) - versions KERNEL 7.22, 8.04, 7.49, 7.53, ... |
| CVE-2022-22542 | MEDIUM | 6.5 | 1.0% | Feb 9, 2022 | S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Ro... |
| CVE-2022-22540 | HIGH | 7.5 | 1.2% | Feb 9, 2022 | SAP NetWeaver AS ABAP (Workplace Server) - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 787, all... |
| CVE-2022-22539 | MEDIUM | 6.5 | 1.0% | Feb 9, 2022 | When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterpr... |
| CVE-2022-22538 | MEDIUM | 6.5 | 1.0% | Feb 9, 2022 | When a user opens a manipulated Adobe Illustrator file format (.ai, ai.x3d) received from untrusted sources in SAP 3D Vi... |
| CVE-2022-22537 | MEDIUM | 6.5 | 0.9% | Feb 9, 2022 | When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visu... |
| CVE-2022-22536 | CRITICAL | 10 | 97.9% | Feb 9, 2022 | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and... |
| CVE-2022-22535 | MEDIUM | 6.5 | 0.8% | Feb 9, 2022 | SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads t... |
| CVE-2022-22534 | MEDIUM | 6.1 | 0.8% | Feb 9, 2022 | Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may exp... |
| CVE-2022-22533 | HIGH | 7.5 | 1.7% | Feb 9, 2022 | Due to improper error handling in SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64... |
| CVE-2022-22532 | CRITICAL | 9.8 | 2.3% | Feb 9, 2022 | In SAP NetWeaver Application Server Java - versions KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC, 7.22, 7.22EXT, 7.49, 7.53, ... |
| CVE-2022-22528 | HIGH | 7.8 | 0.3% | Feb 9, 2022 | SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable... |
| CVE-2022-21825 | HIGH | 7.8 | 0.2% | Feb 9, 2022 | An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection instal... |
| CVE-2022-21226 | MEDIUM | 5.5 | 0.3% | Feb 9, 2022 | Out-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to... |
| CVE-2022-21220 | HIGH | 7.8 | 0.2% | Feb 9, 2022 | Improper restriction of XML external entity for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an a... |
| CVE-2022-21218 | MEDIUM | 5.5 | 0.3% | Feb 9, 2022 | Uncaught exception in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to... |
| CVE-2022-21205 | HIGH | 7.5 | 1.1% | Feb 9, 2022 | Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition befor... |
| CVE-2022-21204 | HIGH | 7.8 | 0.2% | Feb 9, 2022 | Improper permissions for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to po... |
| CVE-2022-21203 | HIGH | 7.8 | 0.2% | Feb 9, 2022 | Improper permissions in the SafeNet Sentinel driver for Intel(R) Quartus(R) Prime Standard Edition before version 21.1 m... |
| CVE-2022-21174 | HIGH | 7.8 | 0.3% | Feb 9, 2022 | Improper access control in a third-party component of Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allo... |
| CVE-2022-21157 | MEDIUM | 5.5 | 0.3% | Feb 9, 2022 | Improper access control in the Intel(R) Smart Campus Android application before version 6.1 may allow authenticated user... |
| CVE-2022-21156 | MEDIUM | 5.5 | 0.2% | Feb 9, 2022 | Access of uninitialized pointer in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenti... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now