2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-2794HIGH7.5Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack.
CVE-2022-1038HIGH7.8A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of pri...
CVE-2022-45797HIGH7.1An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro ...
CVE-2022-41296HIGH8.8IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou...
CVE-2022-3641HIGH8.8Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows ...
CVE-2022-20968HIGH8.8A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could...
CVE-2022-20690HIGH8.8Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter ...
CVE-2022-20689HIGH8.8Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter ...
CVE-2022-4416HIGH8.8A vulnerability was found in RainyGao DocSys. It has been declared as critical. This vulnerability affects the function ...
CVE-2022-46908HIGH7.3SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the ...
CVE-2022-25837HIGH7.5Bluetooth® Pairing in Bluetooth Core Specification v1.0B through v5.3 may permit an unauthenticated MITM to acquire cred...
CVE-2022-25836HIGH7.5Bluetooth® Low Energy Pairing in Bluetooth Core Specification v4.0 through v5.3 may permit an unauthenticated MITM to ac...
CVE-2022-45760HIGH8.8SENS v1.0 is vulnerable to Incorrect Access Control vulnerability.
CVE-2022-45759HIGH8.8SENS v1.0 has a file upload vulnerability.
CVE-2022-45227HIGH7.5The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https://10.10.20.74/lib/. Thi...
CVE-2022-4409HIGH7.5Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.1.9.
CVE-2022-4403HIGH8.8A vulnerability classified as critical was found in SourceCodester Canteen Management System. This vulnerability affects...
CVE-2022-4402HIGH7.2A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the co...
CVE-2022-4398HIGH7.8Integer Overflow or Wraparound in GitHub repository radareorg/radare2 prior to 5.8.0.
CVE-2022-23510HIGH8.8cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL...
CVE-2022-23497HIGH7.5FreshRSS is a free, self-hostable RSS aggregator. User configuration files can be accessed by a remote user. In addition...
CVE-2022-46157HIGH8.8Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119...
CVE-2022-44790HIGH7.5Interspire Email Marketer through 6.5.1 allows SQL Injection via the surveys module. An unauthenticated attacker could s...
CVE-2022-3724HIGH7.5Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or cra...
CVE-2022-3259HIGH7.4Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now