2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-41949MEDIUM4.3DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. In af...
CVE-2022-23494MEDIUM6.1tinymce is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in the alert and c...
CVE-2022-23469MEDIUM6.5Traefik is an open source HTTP reverse proxy and load balancer. Versions prior to 2.9.6 are subject to a potential vulne...
CVE-2022-41717MEDIUM5.3An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contai...
CVE-2022-46831MEDIUM4.9In JetBrains TeamCity between 2022.10 and 2022.10.1 connecting to AWS using the "Default Credential Provider Chain" allo...
CVE-2022-46830MEDIUM5.3In JetBrains TeamCity between 2022.10 and 2022.10.1 a custom STS endpoint allowed internal port scanning.
CVE-2022-46827MEDIUM5.5In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was po...
CVE-2022-46826MEDIUM5.5In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a pa...
CVE-2022-40939MEDIUM4.9In certain Secustation products the administrator account password can be read. This affects V2.5.5.3116-S50-SMA-B201711...
CVE-2022-38599MEDIUM6.5Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user...
CVE-2022-4122MEDIUM5.3A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore r...
CVE-2022-45877MEDIUM5.3OpenHarmony-v3.1.4 and prior versions had an vulnerability. PIN code is transmitted to the peer device in plain text dur...
CVE-2022-45118MEDIUM5.5OpenHarmony-v3.1.2 and prior versions had a vulnerability that telephony in communication subsystem sends public events ...
CVE-2022-3260MEDIUM4.8The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers wo...
CVE-2022-39915MEDIUM5.5Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android ...
CVE-2022-39911MEDIUM6.8Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows atta...
CVE-2022-39910MEDIUM4.2Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data ...
CVE-2022-39909MEDIUM5.5Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.22101...
CVE-2022-39905MEDIUM5.5Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access...
CVE-2022-39901MEDIUM6.5Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network...
CVE-2022-39900MEDIUM4.6Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical attackers to access ...
CVE-2022-39899MEDIUM4.3Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to...
CVE-2022-39897MEDIUM5.5Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the...
CVE-2022-38754MEDIUM5.4A potential vulnerability has been identified in Micro Focus Operations Bridge - Containerized. The vulnerability could ...
CVE-2022-4353MEDIUM5.4A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. Affected by this vulnerability i...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now