2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-48295HIGH7.5The IHwAntiMalPlugin interface lacks permission verification. Successful exploitation of this vulnerability can lead to ...
CVE-2022-48294HIGH7.5The IHwAttestationService interface has a defect in authentication. Successful exploitation of this vulnerability may af...
CVE-2022-48293MEDIUM6.5The Bluetooth module has an OOM vulnerability. Successful exploitation of this vulnerability may affect data confidentia...
CVE-2022-48292MEDIUM6.5The Bluetooth module has an out-of-memory (OOM) vulnerability. Successful exploitation of this vulnerability may affect ...
CVE-2022-48290CRITICAL9.1The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may af...
CVE-2022-48289HIGH7.5The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this v...
CVE-2022-48288HIGH7.5The bundle management module lacks authentication and control mechanisms in some APIs. Successful exploitation of this v...
CVE-2022-48287HIGH7.5The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data in...
CVE-2022-48286HIGH7.5The multi-screen collaboration module has a privilege escalation vulnerability. Successful exploitation of this vulnerab...
CVE-2022-30564MEDIUM5.3Some Dahua embedded products have a vulnerability of unauthorized modification of the device timestamp. By sending a spe...
CVE-2022-43440HIGH7.8Uncontrolled Search Path Element in Checkmk Agent in Tribe29 Checkmk before 2.1.0p1, before 2.0.0p25 and before 1.6.0p29...
CVE-2022-47648HIGH8.8An Improper Access Control vulnerability allows an attacker to access the control panel of the B420 without requiring an...
CVE-2022-45982CRITICAL9.8thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to e...
CVE-2022-38778MEDIUM6.5A flaw (CVE-2022-38900) was discovered in one of Kibana’s third party dependencies, that could allow an authenticated us...
CVE-2022-38777HIGH7.8An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged...
CVE-2022-4450HIGH7.5The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any h...
CVE-2022-4304MEDIUM5.9A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a p...
CVE-2022-34350HIGH7.5IBM API Connect 10.0.0.0 through 10.0.5.0, 10.0.1.0 through 10.0.1.7, and 2018.4.1.0 through 2018.4.1.20 is vulnerable t...
CVE-2022-45755MEDIUM5.4Cross-site scripting (XSS) vulnerability in EyouCMS v1.6.0 allows attackers to execute arbitrary code via the home page ...
CVE-2022-45527CRITICAL9.8File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to d...
CVE-2022-45526CRITICAL9.8SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbi...
CVE-2022-42438HIGH8.8IBM Cloud Pak for Multicloud Management Monitoring 2.0 and 2.3 allows users without admin roles access to admin function...
CVE-2022-35720MEDIUM5.5IBM Sterling External Authentication Server 6.1.0 and IBM Sterling Secure Proxy 6.0.3 uses weaker than expected cryptogr...
CVE-2022-34362MEDIUM4.6 IBM Sterling Secure Proxy 6.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the H...
CVE-2022-41620HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in SeoSamba for WordPress Webmasters plugin <= 1.0.5 versions.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now