2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-41760MEDIUM6.5An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Netwo...
CVE-2022-39822HIGH8.8In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the...
CVE-2022-39820MEDIUM6.5In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/...
CVE-2022-39818HIGH8.8In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via ...
CVE-2022-39337HIGH7.5Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-li...
CVE-2022-47532CRITICAL9.8FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users&section=cpanel&page=list request.
CVE-2022-45377CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload ...
CVE-2022-44684MEDIUM6.5Windows Local Session Manager (LSM) Denial of Service Vulnerability
CVE-2022-47599HIGH7.2Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager – 100% Free & Open Source ...
CVE-2022-47597HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Popup Maker Popup Maker – Popup for opt-ins,...
CVE-2022-43450MEDIUM6.5Authorization Bypass Through User-Controlled Key vulnerability in XWP Stream.This issue affects Stream: from n/a through...
CVE-2022-45809LOW3.7Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs...
CVE-2022-40312MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in GiveWP GiveWP – Donation Plugin and Fundraising Platform.This issue ...
CVE-2022-41677MEDIUM5.3An information disclosure vulnerability was discovered in Bosch IP camera devices allowing an unauthenticated attacker t...
CVE-2022-24351MEDIUM4.7TOCTOU race-condition vulnerability in Insyde InsydeH2O with Kernel 5.2 before version 05.27.29, Kernel 5.3 before versi...
CVE-2022-45365MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Uroševi...
CVE-2022-43843HIGH7.5IBM Spectrum Scale 5.1.5.0 through 5.1.5.1 uses weaker than expected cryptographic algorithms that could allow an attack...
CVE-2022-22942HIGH7.8The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to f...
CVE-2022-27488HIGH8.8A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 thr...
CVE-2022-44543MEDIUM5.3The femanager extension before 5.5.2, 6.x before 6.3.3, and 7.x before 7.0.1 for TYPO3 allows creation of frontend users...
CVE-2022-47375HIGH7.5A vulnerability has been identified in SIMATIC PC-Station Plus (All versions), SIMATIC S7-400 CPU 412-2 PN V7 (All versi...
CVE-2022-47374HIGH7.5A vulnerability has been identified in SIMATIC PC-Station Plus (All versions), SIMATIC S7-400 CPU 412-2 PN V7 (All versi...
CVE-2022-46141MEDIUM5.5A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulne...
CVE-2022-42784MEDIUM6.8A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions >= V8.3), LOGO! 12/24RCEo (6ED1...
CVE-2022-48616HIGH7.5A Huawei data communication product has a command injection vulnerability. Successful exploitation of this vulnerability...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now