2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3431HIGH7.8A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that wa...
CVE-2022-35950MEDIUM4.8OroCommerce is an open-source Business to Business Commerce application. In versions 4.1.0 through 4.1.13, 4.2.0 through...
CVE-2022-33160HIGH7.5IBM Security Directory Suite 8.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to de...
CVE-2022-34355MEDIUM5.5IBM Jazz Foundation (IBM Engineering Lifecycle Management 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2) could disclose sensitiv...
CVE-2022-47175HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in P Royal Royal Elementor Addons and Templates plugin <= 1.3.75 version...
CVE-2022-3248HIGH7.5A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow ...
CVE-2022-4145MEDIUM5.3A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to ...
CVE-2022-36277MEDIUM6.1The 'sReferencia', 'sDescripcion', 'txtCodigo' and 'txtDescripcion' parameters, in the frmGestionStock.aspx and frmEditS...
CVE-2022-36276CRITICAL9.8TCMAN GIM v8.0.1 is vulnerable to a SQL injection via the 'SqlWhere' parameter inside the function 'BuscarESM'. The expl...
CVE-2022-43906MEDIUM5.3IBM Security Guardium 11.5 could disclose sensitive information due to a missing or insecure SameSite attribute for a se...
CVE-2022-4132MEDIUM5.9A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if conf...
CVE-2022-22447HIGH7.5IBM Disconnected Log Collector 1.0 through 1.8.2 is vulnerable to potential security misconfigurations that could disclo...
CVE-2022-47893CRITICAL9.8There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a...
CVE-2022-47892HIGH7.5All versions of NetMan 204 could allow an unauthenticated remote attacker to read a file (config.cgi) containing sensiti...
CVE-2022-47891HIGH8.8All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrat...
CVE-2022-46841HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Oxygen Builder plugin <= 4.4 versions.
CVE-2022-4956HIGH7.8A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part o...
CVE-2022-35908HIGH8.8Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent.
CVE-2022-47187MEDIUM6.1There is a file upload XSS vulnerability in Generex CS141 below 2.06 version. The web application allows file uploading,...
CVE-2022-47186CRITICAL9.1There is an unrestricted upload of file vulnerability in Generex CS141 below 2.06 version. An attacker could upload and/...
CVE-2022-48606HIGH7.5Stability-related vulnerability in the binder background management and control module. Successful exploitation of this ...
CVE-2022-4318HIGH7.8A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a speci...
CVE-2022-4245MEDIUM4.3A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comme...
CVE-2022-4244HIGH7.5A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files ...
CVE-2022-4137MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte ha...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now