2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-48615HIGH7.1An improper access control vulnerability exists in a Huawei datacom product. Attackers can exploit this vulnerability to...
CVE-2022-48614MEDIUM6.1Special:Ask in Semantic MediaWiki before 4.0.2 allows Reflected XSS.
CVE-2022-45362MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in Paytm Paytm Payment Gateway.This issue affects Paytm Payment Gateway...
CVE-2022-24403MEDIUM4.3The TETRA TA61 identity encryption function internally uses a 64-bit value derived exclusively from the SCK (Class 2 net...
CVE-2022-47531HIGH8.8An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows au...
CVE-2022-46480HIGH8.1Incorrect Session Management and Credential Re-use in the Bluetooth LE stack of the Ultraloq UL3 2nd Gen Smart Lock Firm...
CVE-2022-48464MEDIUM5.5In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial ...
CVE-2022-48463MEDIUM5.5In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial ...
CVE-2022-48462MEDIUM5.5In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial ...
CVE-2022-4957MEDIUM6.1A vulnerability was found in librespeed speedtest up to 5.2.4. It has been declared as problematic. Affected by this vul...
CVE-2022-45135CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Cocoon.This...
CVE-2022-42541CRITICAL9.8Remote code execution
CVE-2022-42540CRITICAL9.8Elevation of privilege
CVE-2022-42539HIGH7.5Information disclosure
CVE-2022-42538CRITICAL9.8Elevation of privilege
CVE-2022-42537CRITICAL9.8Remote code execution
CVE-2022-42536CRITICAL9.8Remote code execution
CVE-2022-41678HIGH8.8Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.  In details, in ActiveMQ...
CVE-2022-41951CRITICAL9.8OroPlatform is a PHP Business Application Platform (BAP) designed to make development of custom business applications ea...
CVE-2022-44011MEDIUM6.5An issue was discovered in ClickHouse before 22.9.1.2603. An authenticated user (with the ability to load data) could ca...
CVE-2022-44010HIGH7.5An issue was discovered in ClickHouse before 22.9.1.2603. An attacker could send a crafted HTTP request to the HTTP Endp...
CVE-2022-36777MEDIUM6.5IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.16.0co...
CVE-2022-35638HIGH8.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 is vulnerable to cross-...
CVE-2022-46337CRITICAL9.8A cleverly devised username might bypass LDAP authentication checks. In LDAP-authenticated Derby installations, this co...
CVE-2022-45781HIGH8.8Buffer Overflow vulnerability in Tenda AX1803 v1.0.0.1_2994 and earlier allows attackers to run arbitrary code via /gofo...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now