2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-48605CRITICAL9.8Input verification vulnerability in the fingerprint module. Successful exploitation of this vulnerability will affect co...
CVE-2022-3962MEDIUM4.3A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when...
CVE-2022-4039CRITICAL9.8A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured manage...
CVE-2022-3874CRITICAL9.1A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the forem...
CVE-2022-3596HIGH7.5An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect s...
CVE-2022-3916MEDIUM6.8A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especi...
CVE-2022-1438MEDIUM4.8A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, r...
CVE-2022-45448MEDIUM6.1M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to an arbitrary HTML Document craftin...
CVE-2022-45447MEDIUM6.5M4 PDF plugin for Prestashop sites, in its 3.2.3 version and before, is vulnerable to a directory traversal vulnerabilit...
CVE-2022-47562HIGH7.5Vulnerability in the RCPbind service running on UDP port (111), allowing a remote attacker to create a denial of service...
CVE-2022-47561MEDIUM5.5The web application stores credentials in clear text in the "admin.xml" file, which can be accessed without logging into...
CVE-2022-47560MEDIUM6.5The lack of web request control on ekorCCP and ekorRCI devices allows a potential attacker to create custom requests to ...
CVE-2022-47559HIGH8.8Lack of device control over web requests in ekorCCP and ekorRCI, allowing an attacker to create customised requests to e...
CVE-2022-47558CRITICAL9.8Devices ekorCCP and ekorRCI are vulnerable due to access to the FTP service using default credentials. Exploitation of t...
CVE-2022-47557MEDIUM6.1Vulnerability in ekorCCP and ekorRCI that could allow an attacker with access to the network where the device is located...
CVE-2022-47556MEDIUM6.5Uncontrolled resource consumption in ekorRCI, allowing an attacker with low-privileged access to the web server to send ...
CVE-2022-47555HIGH8.8Operating system command injection in ekorCCP and ekorRCI, which could allow an authenticated attacker to execute comman...
CVE-2022-47554HIGH7.5Exposure of sensitive information in ekorCCP and ekorRCI, potentially allowing a remote attacker to obtain critical info...
CVE-2022-47553HIGH7.5Incorrect authorisation in ekorCCP and ekorRCI, which could allow a remote attacker to obtain resources with sensitive i...
CVE-2022-28357CRITICAL9.8NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action fro...
CVE-2022-3261HIGH7.5A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack o...
CVE-2022-47848HIGH7.5An issue was discovered in Bezeq Vtech NB403-IL version BZ_2.02.07.09.13.01 and Vtech IAD604-IL versions BZ_2.02.07.09.1...
CVE-2022-38636Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-3466MEDIUM5.3The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316...
CVE-2022-20917MEDIUM4.3A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber coul...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now