2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3405 | HIGH | 8.8 | 5.3% | May 3, 2023 | Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following... |
| CVE-2022-30995 | HIGH | 7.5 | 3.3% | May 3, 2023 | Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Prot... |
| CVE-2022-30759 | HIGH | 8.8 | 1.1% | May 2, 2023 | In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to es... |
| CVE-2022-47878 | HIGH | 8.8 | 38.1% | May 2, 2023 | Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authentica... |
| CVE-2022-47877 | MEDIUM | 5.4 | 2.6% | May 2, 2023 | A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web... |
| CVE-2022-47876 | HIGH | 8.8 | 7.0% | May 2, 2023 | The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code v... |
| CVE-2022-47875 | HIGH | 8.8 | 10.2% | May 2, 2023 | A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to ex... |
| CVE-2022-47874 | MEDIUM | 6.5 | 22.7% | May 2, 2023 | Improper Access Control in /tc/rpc in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to view details of dat... |
| CVE-2022-40504 | HIGH | 7.5 | 0.4% | May 2, 2023 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. |
| CVE-2022-33273 | MEDIUM | 5.5 | 0.1% | May 2, 2023 | Information disclosure due to buffer over-read in Trusted Execution Environment while QRKS report generation. |
| CVE-2022-40508 | HIGH | 7.5 | 0.4% | May 2, 2023 | Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is ... |
| CVE-2022-40505 | HIGH | 7.5 | 0.4% | May 2, 2023 | Information disclosure due to buffer over-read in Modem while parsing DNS hostname. |
| CVE-2022-34144 | HIGH | 7.5 | 0.4% | May 2, 2023 | Transient DOS due to reachable assertion in Modem during OSI decode scheduling. |
| CVE-2022-33305 | HIGH | 7.5 | 0.4% | May 2, 2023 | Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH. |
| CVE-2022-33304 | HIGH | 7.5 | 0.4% | May 2, 2023 | Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet. |
| CVE-2022-33292 | HIGH | 7.8 | 0.1% | May 2, 2023 | Memory corruption in Qualcomm IPC due to use after free while receiving the incoming packet and reposting it. |
| CVE-2022-33281 | HIGH | 7.8 | 0.1% | May 2, 2023 | Memory corruption due to improper validation of array index in computer vision while testing EVA kernel without sending ... |
| CVE-2022-25713 | HIGH | 7.8 | 0.1% | May 2, 2023 | Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exp... |
| CVE-2022-48483 | HIGH | 7.5 | 1.7% | May 2, 2023 | 3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 fil... |
| CVE-2022-48482 | HIGH | 7.5 | 1.8% | May 2, 2023 | 3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certa... |
| CVE-2022-35898 | CRITICAL | 9.8 | 0.6% | May 1, 2023 | OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows... |
| CVE-2022-4568 | HIGH | 7 | 0.2% | May 1, 2023 | A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges. |
| CVE-2022-48186 | MEDIUM | 6.2 | 0.3% | May 1, 2023 | A certificate validation vulnerability exists in the Baiying Android application which could lead to information disclos... |
| CVE-2022-46365 | CRITICAL | 9.1 | 1.5% | May 1, 2023 | Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be pas... |
| CVE-2022-45802 | CRITICAL | 9.8 | 1.3% | May 1, 2023 | Streampark allows any users to upload a jar as application, but there is no mandatory verification of the uploaded file ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now