2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45801 | MEDIUM | 5.4 | 1.1% | May 1, 2023 | Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web ba... |
| CVE-2022-43871 | MEDIUM | 5.4 | 0.4% | Apr 29, 2023 | IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability all... |
| CVE-2022-41736 | HIGH | 7.8 | 0.2% | Apr 29, 2023 | IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0 contains an unspecified vulnerability that... |
| CVE-2022-31643 | MEDIUM | 5.5 | 0.2% | Apr 28, 2023 | A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow los... |
| CVE-2022-41400 | CRITICAL | 9.8 | 0.6% | Apr 28, 2023 | Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection st... |
| CVE-2022-41399 | HIGH | 7.5 | 0.6% | Apr 28, 2023 | The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") t... |
| CVE-2022-41398 | HIGH | 7.5 | 0.5% | Apr 28, 2023 | The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accomp... |
| CVE-2022-41397 | CRITICAL | 9.8 | 0.7% | Apr 28, 2023 | The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish ... |
| CVE-2022-38583 | HIGH | 7.8 | 0.3% | Apr 28, 2023 | On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Serve... |
| CVE-2022-48481 | HIGH | 7.8 | 0.2% | Apr 28, 2023 | In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible |
| CVE-2022-25091 | MEDIUM | 5.3 | 0.6% | Apr 27, 2023 | Infopop Ultimate Bulletin Board up to v5.47a was discovered to allow all messages posted inside private forums to be dis... |
| CVE-2022-38730 | MEDIUM | 6.3 | 0.3% | Apr 27, 2023 | Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerB... |
| CVE-2022-37326 | HIGH | 7.8 | 0.3% | Apr 27, 2023 | Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 wind... |
| CVE-2022-34292 | HIGH | 7.1 | 0.3% | Apr 27, 2023 | Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/cr... |
| CVE-2022-31647 | HIGH | 7.1 | 0.3% | Apr 27, 2023 | Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 AP... |
| CVE-2022-47758 | CRITICAL | 9.8 | 1.3% | Apr 27, 2023 | Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS h... |
| CVE-2022-45876 | MEDIUM | 5.5 | 3.3% | Apr 26, 2023 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft... |
| CVE-2022-45456 | HIGH | 7.5 | 0.3% | Apr 26, 2023 | Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macO... |
| CVE-2022-44232 | HIGH | 7.5 | 0.7% | Apr 26, 2023 | libming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of serv... |
| CVE-2022-27979 | MEDIUM | 5.4 | 0.5% | Apr 26, 2023 | A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML v... |
| CVE-2022-27978 | HIGH | 7.5 | 1.1% | Apr 26, 2023 | Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a... |
| CVE-2022-25278 | MEDIUM | 6.5 | 0.6% | Apr 26, 2023 | Under certain circumstances, the Drupal core form API evaluates form element access incorrectly. This may lead to a user... |
| CVE-2022-25277 | HIGH | 7.2 | 1.4% | Apr 26, 2023 | Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading a... |
| CVE-2022-25276 | MEDIUM | 6.1 | 0.5% | Apr 26, 2023 | The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed ... |
| CVE-2022-39989 | CRITICAL | 9.8 | 0.8% | Apr 26, 2023 | An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now