2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-48595HIGH8.8A SQL injection vulnerability exists in the “ticket template watchers” feature of the ScienceLogic SL1 that takes unsani...
CVE-2022-48594HIGH8.8A SQL injection vulnerability exists in the “ticket watchers email” feature of the ScienceLogic SL1 that takes unsanitiz...
CVE-2022-48593HIGH8.8A SQL injection vulnerability exists in the “topology data service” feature of the ScienceLogic SL1 that takes unsanitiz...
CVE-2022-48592HIGH8.8A SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report” feature of the Science...
CVE-2022-48591HIGH8.8A SQL injection vulnerability exists in the vendor_state parameter of the “vendor print report” feature of the ScienceLo...
CVE-2022-48590HIGH8.8A SQL injection vulnerability exists in the “admin dynamic app mib errors” feature of the ScienceLogic SL1 that takes un...
CVE-2022-48589HIGH8.8A SQL injection vulnerability exists in the “reporting job editor” feature of the ScienceLogic SL1 that takes unsanitize...
CVE-2022-48588HIGH8.8A SQL injection vulnerability exists in the “schedule editor decoupled” feature of the ScienceLogic SL1 that takes unsan...
CVE-2022-48587HIGH8.8A SQL injection vulnerability exists in the “schedule editor” feature of the ScienceLogic SL1 that takes unsanitized use...
CVE-2022-48586HIGH8.8A SQL injection vulnerability exists in the “json walker” feature of the ScienceLogic SL1 that takes unsanitized user‐co...
CVE-2022-48585HIGH8.8A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized ...
CVE-2022-48584HIGH8.8A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes u...
CVE-2022-48583HIGH8.8A command injection vulnerability exists in the dashboard scheduler feature of the ScienceLogic SL1 that takes unsanitiz...
CVE-2022-48582HIGH8.8A command injection vulnerability exists in the ticket report generate feature of the ScienceLogic SL1 that takes unsani...
CVE-2022-48581HIGH8.8A command injection vulnerability exists in the “dash export” feature of the ScienceLogic SL1 that takes unsanitized use...
CVE-2022-48580HIGH8.8A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsaniti...
CVE-2022-47185HIGH7.5Improper input validation vulnerability on the range header in Apache Software Foundation Apache Traffic Server.This iss...
CVE-2022-45821MEDIUM5.4Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in NooTheme Noo Timetable plugin <= 2.1.3 versions.
CVE-2022-40510CRITICAL9.8Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.
CVE-2022-39062HIGH7.8A vulnerability has been identified in SICAM TOOLBOX II (All versions < V07.10). Affected applications do not properly s...
CVE-2022-38795MEDIUM6.5In Gitea through 1.17.1, repo cloning can occur in the migration function.
CVE-2022-48579HIGH7.5UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.
CVE-2022-47351MEDIUM4.4In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial ...
CVE-2022-47350MEDIUM4.4In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial ...
CVE-2022-46782HIGH7.8An issue was discovered in Stormshield SSL VPN Client before 3.2.0. A logged-in user, able to only launch the VPNSSL Cli...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now