2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-45766CRITICAL9.1Hardcoded credentials in Global Facilities Management Software (GFMS) Version 3 software distributed by Key Systems Mana...
CVE-2022-46650MEDIUM4.9Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACE...
CVE-2022-46649HIGH8.8Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to e...
CVE-2022-4903HIGH8.1A vulnerability was found in CodenameOne 7.0.70. It has been classified as problematic. Affected is an unknown function....
CVE-2022-24410MEDIUM4.2 Dell BIOS contains an information exposure vulnerability. An unauthenticated local attacker with physical access to the...
CVE-2022-34454MEDIUM6.7Dell PowerScale OneFS, versions 8.2.x-9.3.x, contain a heap-based buffer overflow. A local privileged malicious user cou...
CVE-2022-34452LOW2.7 PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerabil...
CVE-2022-43501CRITICAL9.1KASAGO TCP/IP stack provided by Zuken Elmic generates ISNs(Initial Sequence Number) for TCP connections from an insuffic...
CVE-2022-45699CRITICAL9.8Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attack...
CVE-2022-3568HIGH8.8The ImageMagick Engine plugin for WordPress is vulnerable to deserialization of untrusted input via the 'cli_path' param...
CVE-2022-21940MEDIUM6.1Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool...
CVE-2022-21939MEDIUM6.1Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 pr...
CVE-2022-44572HIGH7.5A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0....
CVE-2022-44571HIGH7.5There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2...
CVE-2022-44570HIGH7.5A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can ...
CVE-2022-44566HIGH7.5A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outsi...
CVE-2022-43552MEDIUM5.9A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports...
CVE-2022-43550CRITICAL9.8A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching ...
CVE-2022-48302HIGH7.5The AMS module has a vulnerability of lacking permission verification in APIs.Successful exploitation of this vulnerabil...
CVE-2022-48301HIGH7.5The bundle management module lacks permission verification in some APIs. Successful exploitation of this vulnerability m...
CVE-2022-48300HIGH7.5The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect...
CVE-2022-48299HIGH7.5The WMS module lacks the authentication mechanism in some APIs. Successful exploitation of this vulnerability may affect...
CVE-2022-48298HIGH7.5The geofencing kernel code does not verify the length of the input data. Successful exploitation of this vulnerability m...
CVE-2022-48297HIGH7.5The geofencing kernel code has a vulnerability of not verifying the length of the input data. Successful exploitation of...
CVE-2022-48296MEDIUM5.3The SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now