2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-45459HIGH7.5Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agen...
CVE-2022-45458HIGH7.5Sensitive information disclosure and manipulation due to improper certification validation. The following products are a...
CVE-2022-45457HIGH7.5Sensitive information disclosure and manipulation due to improper certification validation. The following products are a...
CVE-2022-45453HIGH7.5TLS/SSL weak cipher suites enabled. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) befor...
CVE-2022-45452HIGH7.8Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Agent (Windo...
CVE-2022-45450HIGH7.5Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Ac...
CVE-2022-4870MEDIUM5.3In affected versions of Octopus Deploy it is possible to discover network details via error message
CVE-2022-45144MEDIUM6.1Algoo Tracim before 4.4.2 allows XSS via HTML file upload.
CVE-2022-42336LOW3.3Mishandling of guest SSBD selection on AMD hardware The current logic to set SSBD on AMD Family 17h and Hygon Family 18h...
CVE-2022-4774CRITICAL9.8The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allo...
CVE-2022-47393MEDIUM6.5An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vuln...
CVE-2022-47392MEDIUM6.5An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce C...
CVE-2022-4048HIGH7.7Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated l...
CVE-2022-47937CRITICAL9.8Improper input validation in the Apache Sling Commons JSON bundle allows an attacker to trigger unexpected errors by sup...
CVE-2022-47391HIGH7.5In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation v...
CVE-2022-47390HIGH8.8An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component o...
CVE-2022-47389HIGH8.8An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component o...
CVE-2022-47388HIGH8.8An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component o...
CVE-2022-47387HIGH8.8An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of...
CVE-2022-47386HIGH8.8An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component o...
CVE-2022-47385HIGH8.8An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpAppForce Component o...
CVE-2022-47384HIGH8.8An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of...
CVE-2022-47383HIGH8.8An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component o...
CVE-2022-47382HIGH8.8An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of...
CVE-2022-47381HIGH8.8An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in multiple CODESYS products in...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now