2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-40237HIGH7.5IBM MQ for HPE NonStop 8.1.0 is vulnerable to a denial of service attack due to an error within the CCDT and channel syn...
CVE-2022-34910MEDIUM5.5An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It uses a local database to store dat...
CVE-2022-34909CRITICAL9.1An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It allows SQL Injection, by which an ...
CVE-2022-34908HIGH7.5An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses an authentication mechan...
CVE-2022-31405MEDIUM6.5MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext.
CVE-2022-48363HIGH7.5In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Dra...
CVE-2022-48362HIGH8.8Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName ...
CVE-2022-2024CRITICAL9.8OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.
CVE-2022-23535CRITICAL9.8LiteDB is a small, fast and lightweight .NET NoSQL embedded database. Versions prior to 5.0.13 are subject to Deserializ...
CVE-2022-44310HIGH7.5In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obt...
CVE-2022-4203MEDIUM4.9A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note...
CVE-2022-43923MEDIUM5.5IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user...
CVE-2022-48345MEDIUM6.1sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
CVE-2022-1607HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plan...
CVE-2022-46440MEDIUM5.5ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.
CVE-2022-46785MEDIUM6.1SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 1 of 2).
CVE-2022-46784MEDIUM6.1SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows open redirection. (The issue was originally found in 5.5....
CVE-2022-36231CRITICAL9.8pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.
CVE-2022-4492HIGH7.5The undertow client is not checking the server identity presented by the server certificate in https connections. This i...
CVE-2022-46786MEDIUM5.4SquaredUp Dashboard Server SCOM edition before 5.7.1 GA allows XSS (issue 2 of 2).
CVE-2022-3219LOW3.3GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signature...
CVE-2022-2176Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2022-48344MEDIUM6.1In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the group creation process.
CVE-2022-48343MEDIUM6.1In JetBrains TeamCity before 2022.10.2 there was an XSS vulnerability in the user creation process.
CVE-2022-48342CRITICAL9.8In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now