2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-26841MEDIUM5.5Insufficient control flow management for the Intel(R) SGX SDK software for Linux before version 2.16.100.1 may allow an ...
CVE-2022-26509MEDIUM5.5Improper conditions check in the Intel(R) SGX SDK software may allow a privileged user to potentially enable information...
CVE-2022-26343MEDIUM6.7Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially ena...
CVE-2022-21216MEDIUM6.8Insufficient granularity of access control in out-of-band management in some Intel(R) Atom and Intel Xeon Scalable Proce...
CVE-2022-43954MEDIUM6.5An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0....
CVE-2022-42472MEDIUM5.4A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2...
CVE-2022-41334MEDIUM6.1An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7...
CVE-2022-38378MEDIUM6An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiPro...
CVE-2022-38376MEDIUM6.1Multiple improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilities [CWE-79] i...
CVE-2022-30304MEDIUM6.1An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to...
CVE-2022-30300MEDIUM6.5A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions...
CVE-2022-30299MEDIUM4.3A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versio...
CVE-2022-48306MEDIUM6.8Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows ...
CVE-2022-27891MEDIUM5.3Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active sessio...
CVE-2022-38731MEDIUM4.3Qaelum DOSE 18.08 through 21.1 before 21.2 allows Directory Traversal via the loadimages name parameter. It allows a use...
CVE-2022-45543MEDIUM6.1Cross site scripting (XSS) vulnerability in DiscuzX 3.4 allows attackers to execute arbitrary code via the datetline, ti...
CVE-2022-45587MEDIUM5.5Stack overflow vulnerability in function gmalloc in goo/gmem.cc in xpdf 4.04, allows local attackers to cause a denial o...
CVE-2022-45586MEDIUM5.5Stack overflow vulnerability in function Dict::find in xpdf/Dict.cc in xpdf 4.04, allows local attackers to cause a deni...
CVE-2022-45154MEDIUM5.5A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Lin...
CVE-2022-25978MEDIUM6.1All versions of the package github.com/usememos/memos/server are vulnerable to Cross-site Scripting (XSS) due to insuffi...
CVE-2022-47373MEDIUM6.1Reflected Cross Site Scripting in Search Functionality of Module Library in Pandora FMS Console v766 and lower. This vul...
CVE-2022-47372MEDIUM5.4Stored cross-site scripting vulnerability in the Create event section in Pandora FMS Console v766 and lower. An attacker...
CVE-2022-45437MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandor...
CVE-2022-45436MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Artica PFMS Pandor...
CVE-2022-41564MEDIUM6.5The Hawk Console component of TIBCO Software Inc.'s TIBCO Hawk and TIBCO Operational Intelligence Hawk RedTail contains ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now