2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-45801MEDIUM5.4Apache StreamPark 1.0.0 to 2.0.0 have a LDAP injection vulnerability. LDAP Injection is an attack used to exploit web ba...
CVE-2022-43871MEDIUM5.4IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to cross-site scripting. This vulnerability all...
CVE-2022-41736HIGH7.8IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0 contains an unspecified vulnerability that...
CVE-2022-31643MEDIUM5.5A potential security vulnerability has been identified in the system BIOS for certain HP PC products which may allow los...
CVE-2022-41400CRITICAL9.8Sage 300 through 2022 uses a hard-coded 40-byte blowfish key to encrypt and decrypt user passwords and SQL connection st...
CVE-2022-41399HIGH7.5The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") t...
CVE-2022-41398HIGH7.5The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accomp...
CVE-2022-41397CRITICAL9.8The optional Web Screens and Global Search features for Sage 300 through version 2022 use a hard-coded 40-byte blowfish ...
CVE-2022-38583HIGH7.8On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Serve...
CVE-2022-48481HIGH7.8In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible
CVE-2022-25091MEDIUM5.3Infopop Ultimate Bulletin Board up to v5.47a was discovered to allow all messages posted inside private forums to be dis...
CVE-2022-38730MEDIUM6.3Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerB...
CVE-2022-37326HIGH7.8Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 wind...
CVE-2022-34292HIGH7.1Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/cr...
CVE-2022-31647HIGH7.1Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 AP...
CVE-2022-47758CRITICAL9.8Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS h...
CVE-2022-45876MEDIUM5.5Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially craft...
CVE-2022-45456HIGH7.5Denial of service due to unauthenticated API endpoint. The following products are affected: Acronis Agent (Windows, macO...
CVE-2022-44232HIGH7.5libming 0.4.8 0.4.8 is vulnerable to Buffer Overflow. In getInt() in decompile.c unknown type may lead to denial of serv...
CVE-2022-27979MEDIUM5.4A cross-site scripting (XSS) vulnerability in ToolJet v1.6.0 allows attackers to execute arbitrary web scripts or HTML v...
CVE-2022-27978HIGH7.5Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a...
CVE-2022-25278MEDIUM6.5Under certain circumstances, the Drupal core form API evaluates form element access incorrectly. This may lead to a user...
CVE-2022-25277HIGH7.2Drupal core sanitizes filenames with dangerous extensions upon upload (reference: SA-CORE-2020-012) and strips leading a...
CVE-2022-25276MEDIUM6.1The Media oEmbed iframe route does not properly validate the iframe domain setting, which allows embeds to be displayed ...
CVE-2022-39989CRITICAL9.8An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now