2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0183MEDIUM4.6Missing encryption of sensitive data vulnerability in 'MIRUPASS' PW10 firmware all versions and 'MIRUPASS' PW20 firmware...
CVE-2022-0182MEDIUM5.4Stored cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote authenticate...
CVE-2022-0181MEDIUM6.1Reflected cross-site scripting vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attacker ...
CVE-2022-0180HIGH8.8Cross-site request forgery (CSRF) vulnerability in Quiz And Survey Master versions prior to 7.3.7 allows a remote attack...
CVE-2022-0131LOW3.3Jimoty App for Android versions prior to 3.7.42 uses a hard-coded API key for an external service. By exploiting this vu...
CVE-2022-0239CRITICAL9.8corenlp is vulnerable to Improper Restriction of XML External Entity Reference
CVE-2022-23304CRITICAL9.8The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel atta...
CVE-2022-23303CRITICAL9.8The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks ...
CVE-2022-0235MEDIUM6.1node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2022-0238MEDIUM4.3phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2022-23178CRITICAL9.8An issue was discovered on Crestron HD-MD4X2-4K-E 1.0.0.2159 devices. When the administrative web interface of the HDMI ...
CVE-2022-23095HIGH7.8Open Design Alliance Drawings SDK before 2022.12.1 mishandles the loading of JPG files. Unchecked input data from a craf...
CVE-2022-23094HIGH7.5Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon cras...
CVE-2022-22531HIGH8.1The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check ...
CVE-2022-22530HIGH8.1The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check ...
CVE-2022-22529MEDIUM6.1SAP Enterprise Threat Detection (ETD) - version 2.0, does not sufficiently encode user-controlled inputs which may lead ...
CVE-2022-22290MEDIUM6.5Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoo...
CVE-2022-21137HIGH7.8Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project f...
CVE-2022-0130HIGH8.1Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow ...
CVE-2022-0226MEDIUM4.3livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2022-23227CRITICAL9.8NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to...
CVE-2022-0224CRITICAL9.8dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
CVE-2022-21685MEDIUM6.5Frontier is Substrate's Ethereum compatibility layer. Prior to commit number `8a93fdc6c9f4eb1d2f2a11b7ff1d12d70bf5a664`,...
CVE-2022-21681HIGH7.5Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cau...
CVE-2022-21680HIGH7.5Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastro...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now