2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-30299MEDIUM4.3A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versio...
CVE-2022-29054LOW3.3A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet Fo...
CVE-2022-27489HIGH7.2A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7...
CVE-2022-27482HIGH7.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC versio...
CVE-2022-26115HIGH7.5A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may a...
CVE-2022-48308LOW3.7It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net....
CVE-2022-48307LOW3.7It was discovered that the Magritte-ftp was not verifying hostnames in TLS certificates due to a misuse of the javax.net...
CVE-2022-48306MEDIUM6.8Improper Validation of Certificate with Host Mismatch vulnerability in Gotham Chat IRC helper of Palantir Gotham allows ...
CVE-2022-27897HIGH7.5Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously...
CVE-2022-27892HIGH7.5Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would have allowed an attacker to ...
CVE-2022-27891MEDIUM5.3Palantir Gotham included an unauthenticated endpoint that listed all active usernames on the stack with an active sessio...
CVE-2022-27890HIGH7.4It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net....
CVE-2022-3843CRITICAL9.1In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without author...
CVE-2022-43969CRITICAL9.1Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.
CVE-2022-38731MEDIUM4.3Qaelum DOSE 18.08 through 21.1 before 21.2 allows Directory Traversal via the loadimages name parameter. It allows a use...
CVE-2022-40016HIGH7.5Use After Free (UAF) vulnerability in ireader media-server before commit 3e0f63f1d3553f75c7d4eb32fa7c7a1976a9ff84 in lib...
CVE-2022-38935HIGH8.8An issue was discovered in NiterForum version 2.5.0-beta in /src/main/java/cn/niter/forum/api/SsoApi.java and /src/main/...
CVE-2022-38868HIGH7.2SQL Injection vulnerability in Ehoney version 2.0.0 in models/protocol.go and models/images.go, allows attackers to exec...
CVE-2022-38867HIGH8.8SQL Injection vulnerability in rttys versions 4.0.0, 4.0.1, 4.0.2, and 4.4.x in api.go, allows attackers to execute arbi...
CVE-2022-45546HIGH7.5Information Disclosure in Authentication Component of ScreenCheck BadgeMaker 2.6.2.0 application allows internal attacke...
CVE-2022-45543MEDIUM6.1Cross site scripting (XSS) vulnerability in DiscuzX 3.4 allows attackers to execute arbitrary code via the datetline, ti...
CVE-2022-42455HIGH7.8ASUS EC Tool driver (aka d.sys) 1beb15c90dcf7a5234ed077833a0a3e900969b60be1d04fcebce0a9f8994bdbb, as signed by ASUS and ...
CVE-2022-47508HIGH7.5Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but s...
CVE-2022-47507HIGH7.2SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa...
CVE-2022-47506HIGH7.8SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversar...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now