2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-20962HIGH8.8A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated...
CVE-2022-20961HIGH8.8A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic...
CVE-2022-20960HIGH7.5A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote...
CVE-2022-20958HIGH8.8A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthent...
CVE-2022-20956HIGH8.8A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2022-20868HIGH8.8A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Mana...
CVE-2022-41671HIGH7.8A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that al...
CVE-2022-41670HIGH7.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGI...
CVE-2022-41669HIGH7.8A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows...
CVE-2022-41668HIGH7.8A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load ...
CVE-2022-41667HIGH7.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allow...
CVE-2022-3340HIGH7.2XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administra...
CVE-2022-33684HIGH8.1The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Crede...
CVE-2022-41666HIGH7.8A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user...
CVE-2022-43571HIGH8.8In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through t...
CVE-2022-43574HIGH7.5"IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignm...
CVE-2022-43495HIGH7.5OpenHarmony-v3.1.2 and prior versions had a DOS vulnerability in distributedhardware_device_manager when joining a netwo...
CVE-2022-43063HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-43062HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-43061HIGH7.2Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the co...
CVE-2022-42745HIGH7.5CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because th...
CVE-2022-35717HIGH7.8"IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on th...
CVE-2022-30608HIGH8.8"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to exe...
CVE-2022-25952HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Keywordrush Content Egg plugin <= 5.4.0 on WordPress.
CVE-2022-3258HIGH8.8Incorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on Windows allows Authentic...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now