2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-46396LOW3.3An issue was discovered in the Arm Mali Kernel Driver. A non-privileged user can make improper GPU memory processing ope...
CVE-2022-43955MEDIUM6.1An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0....
CVE-2022-43952MEDIUM5.4An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiA...
CVE-2022-43951HIGH7.5An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiNAC 9.4.1 and below, 9.2.6...
CVE-2022-43948HIGH7.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio...
CVE-2022-43947HIGH8.8An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 t...
CVE-2022-43946HIGH8.1Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and ...
CVE-2022-42477MEDIUM5.5An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6...
CVE-2022-42470HIGH7.8A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 an...
CVE-2022-42469MEDIUM4.3A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate version 7.2.3 and below, version 7.0.9 and belo...
CVE-2022-41331CRITICAL9.8A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before ver...
CVE-2022-41330MEDIUM6.1An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortin...
CVE-2022-40682HIGH7.8A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0....
CVE-2022-40679HIGH7.8An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions...
CVE-2022-35850MEDIUM6.1An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versio...
CVE-2022-27487HIGH8.8A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2...
CVE-2022-27485MEDIUM6.5A improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-89] in Fortine...
CVE-2022-43770HIGH8.1 Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perf...
CVE-2022-3695MEDIUM6.1 Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.3.0.0, 9.2.0.4 and 8.3.0.27 allow a malicious URL...
CVE-2022-47468MEDIUM5.5In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47467MEDIUM5.5In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47466MEDIUM5.5In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47465MEDIUM5.5In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.
CVE-2022-47464MEDIUM5.5In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.
CVE-2022-47463MEDIUM5.5In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now