2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-46396 | LOW | 3.3 | 0.2% | Apr 11, 2023 | An issue was discovered in the Arm Mali Kernel Driver. A non-privileged user can make improper GPU memory processing ope... |
| CVE-2022-43955 | MEDIUM | 6.1 | 0.6% | Apr 11, 2023 | An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.... |
| CVE-2022-43952 | MEDIUM | 5.4 | 0.4% | Apr 11, 2023 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiA... |
| CVE-2022-43951 | HIGH | 7.5 | 0.6% | Apr 11, 2023 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiNAC 9.4.1 and below, 9.2.6... |
| CVE-2022-43948 | HIGH | 7.8 | 0.6% | Apr 11, 2023 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio... |
| CVE-2022-43947 | HIGH | 8.8 | 0.4% | Apr 11, 2023 | An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 t... |
| CVE-2022-43946 | HIGH | 8.1 | 0.7% | Apr 11, 2023 | Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and ... |
| CVE-2022-42477 | MEDIUM | 5.5 | 0.2% | Apr 11, 2023 | An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6... |
| CVE-2022-42470 | HIGH | 7.8 | 0.3% | Apr 11, 2023 | A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 an... |
| CVE-2022-42469 | MEDIUM | 4.3 | 0.4% | Apr 11, 2023 | A permissive list of allowed inputs vulnerability [CWE-183] in FortiGate version 7.2.3 and below, version 7.0.9 and belo... |
| CVE-2022-41331 | CRITICAL | 9.8 | 1.3% | Apr 11, 2023 | A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before ver... |
| CVE-2022-41330 | MEDIUM | 6.1 | 0.6% | Apr 11, 2023 | An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortin... |
| CVE-2022-40682 | HIGH | 7.8 | 0.2% | Apr 11, 2023 | A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.... |
| CVE-2022-40679 | HIGH | 7.8 | 0.2% | Apr 11, 2023 | An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions... |
| CVE-2022-35850 | MEDIUM | 6.1 | 0.5% | Apr 11, 2023 | An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versio... |
| CVE-2022-27487 | HIGH | 8.8 | 1.0% | Apr 11, 2023 | A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2... |
| CVE-2022-27485 | MEDIUM | 6.5 | 0.6% | Apr 11, 2023 | A improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-89] in Fortine... |
| CVE-2022-43770 | HIGH | 8.1 | 0.5% | Apr 11, 2023 | Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27 does not correctly perf... |
| CVE-2022-3695 | MEDIUM | 6.1 | 0.4% | Apr 11, 2023 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.3.0.0, 9.2.0.4 and 8.3.0.27 allow a malicious URL... |
| CVE-2022-47468 | MEDIUM | 5.5 | 0.1% | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. |
| CVE-2022-47467 | MEDIUM | 5.5 | 0.1% | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. |
| CVE-2022-47466 | MEDIUM | 5.5 | 0.1% | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. |
| CVE-2022-47465 | MEDIUM | 5.5 | 0.1% | Apr 11, 2023 | In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service. |
| CVE-2022-47464 | MEDIUM | 5.5 | 0.1% | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. |
| CVE-2022-47463 | MEDIUM | 5.5 | 0.1% | Apr 11, 2023 | In telecom service, there is a missing permission check. This could lead to local denial of service in telecom service. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now