2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-34385MEDIUM5.5 SupportAssist for Home PCs (version 3.11.4 and prior) and  SupportAssist for Business PCs (version 3.2.0 and prior) con...
CVE-2022-44261MEDIUM6.1Avery Dennison Monarch Printer M9855 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-34377MEDIUM6.7 Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. ...
CVE-2022-34376MEDIUM5.5 Dell PowerEdge BIOS and Dell Precision BIOS contain an improper input validation vulnerability. A local authenticated...
CVE-2022-34366MEDIUM6.5 Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerabili...
CVE-2022-34364MEDIUM4.4 Dell BSAFE SSL-J, versions before 6.5 and version 7.0 contain a debug message revealing unnecessary information vulne...
CVE-2022-33934MEDIUM4.8 Dell PowerScale OneFS, versions 8.2.x through 9.4.x contain multiple stored cross-site scripting vulnerabilities. A rem...
CVE-2022-46650MEDIUM4.9Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACE...
CVE-2022-24410MEDIUM4.2 Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the...
CVE-2022-34454MEDIUM6.7Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user cou...
CVE-2022-21940MEDIUM6.1Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool...
CVE-2022-21939MEDIUM6.1Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 pr...
CVE-2022-43552MEDIUM5.9A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports...
CVE-2022-48296MEDIUM5.3The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users...
CVE-2022-48293MEDIUM6.5The Bluetooth module has an OOM vulnerability. Successful exploitation of this vulnerability may affect data confidentia...
CVE-2022-48292MEDIUM6.5The Bluetooth module has an out-of-memory (OOM) vulnerability. Successful exploitation of this vulnerability may affect ...
CVE-2022-30564MEDIUM5.3Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a spe...
CVE-2022-38778MEDIUM6.5A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated us...
CVE-2022-4304MEDIUM5.9A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a p...
CVE-2022-45755MEDIUM5.4Cross-site scripting (XSS) vulnerability in EyouCMS v1.6.0 allows attackers to execute arbitrary code via the home page ...
CVE-2022-35720MEDIUM5.5IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptogr...
CVE-2022-34362MEDIUM4.6 IBM Sterling Secure Proxy 6.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the H...
CVE-2022-2094MEDIUM6.1The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back ...
CVE-2022-45192MEDIUM6.5An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of servi...
CVE-2022-45191MEDIUM6.5An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of servi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now