2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-41349MEDIUM6.1In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to R...
CVE-2022-41348MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via the onerror attribute of an IMG element, le...
CVE-2022-33918MEDIUM5.5Dell GeoDrive, Versions 2.1 - 2.2, contains an information disclosure vulnerability. An authenticated non-admin user cou...
CVE-2022-32484MEDIUM4.4Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privilege...
CVE-2022-32483MEDIUM4.4Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privilege...
CVE-2022-42087MEDIUM6.5Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function f...
CVE-2022-42086MEDIUM6.5Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function T...
CVE-2022-42078MEDIUM6.5Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fr...
CVE-2022-42077MEDIUM6.5Tenda AC1206 US_AC1206V1.0RTL_V15.03.06.23_multi_TD01 is vulnerable to Cross Site Request Forgery (CSRF) via function fr...
CVE-2022-2249MEDIUM6.7Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local ad...
CVE-2022-42715MEDIUM6.1A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted C...
CVE-2022-3464MEDIUM6.1A vulnerability classified as problematic has been found in puppyCMS up to 5.1. This affects an unknown part of the file...
CVE-2022-2720MEDIUM5.3In affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, se...
CVE-2022-41606MEDIUM6.5HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid ...
CVE-2022-40440MEDIUM6.1mxGraph v4.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the setTooltips() function.
CVE-2022-41550MEDIUM6.5GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header.
CVE-2022-41210MEDIUM5.2SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program whic...
CVE-2022-41209MEDIUM5.2SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusio...
CVE-2022-41206MEDIUM5.4SAP BusinessObjects Business Intelligence platform (Analysis for OLAP) - versions 420, 430, allows an authenticated atta...
CVE-2022-41183MEDIUM5.5Due to lack of proper memory management, when a victim opens manipulated Windows Cursor File (.cur, ico.x3d) file receiv...
CVE-2022-41182MEDIUM5.5Due to lack of proper memory management, when a victim opens manipulated Parasolid Part and Assembly (.x_b, CoreCadTrans...
CVE-2022-41181MEDIUM5.5Due to lack of proper memory management, when a victim opens manipulated Portable Document Format (.pdf, PDFPublishing.d...
CVE-2022-41178MEDIUM5.5Due to lack of proper memory management, when a victim opens manipulated Iges Part and Assembly (.igs, .iges, CoreCadTra...
CVE-2022-41176MEDIUM5.5Due to lack of proper memory management, when a victim opens manipulated Enhanced Metafile (.emf, emf.x3d) file received...
CVE-2022-41174MEDIUM5.5Due to lack of proper memory management, when a victim opens manipulated Right Hemisphere Material (.rhm, rh.x3d) file r...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now