2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-43765HIGH7.5B&R APROL versions < R 4.2-07 doesn’t process correctly specially formatted data packages sent to port 55502/tcp, which ...
CVE-2022-43764CRITICAL9.8Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07...
CVE-2022-43763HIGH7.5Insufficient check of preconditions could lead to Denial of Service conditions when calling commands on the Tbase server...
CVE-2022-43762CRITICAL9.8 Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages
CVE-2022-43761HIGH7.5Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and ch...
CVE-2022-2094MEDIUM6.1The Yellow Yard Searchbar WordPress plugin before 2.8.2 does not escape some URL parameters before outputting them back ...
CVE-2022-45192MEDIUM6.5An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of servi...
CVE-2022-45191MEDIUM6.5An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of servi...
CVE-2022-45190MEDIUM5.3An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can bypass passkey entry in...
CVE-2022-40480MEDIUM6.5Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers...
CVE-2022-47418MEDIUM5.4LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site script...
CVE-2022-47419MEDIUM5.4An XSS vulnerability was discovered in the Mayan EDMS DMS. Successful XSS exploitation was observed in the in-product ta...
CVE-2022-47417MEDIUM5.4LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site script...
CVE-2022-47416MEDIUM5.4LogicalDOC Enterprise is vulnerable to a stored (persistent, or "Type II") cross-site scripting (XSS) condition in the i...
CVE-2022-47415MEDIUM5.4LogicalDOC Enterprise and Community Edition (CE) are vulnerable to a stored (persistent, or "Type II") cross-site script...
CVE-2022-47414MEDIUM5.4 If an attacker has access to the console for OpenKM (and is authenticated), a stored XSS vulnerability is reachable in ...
CVE-2022-47413MEDIUM5.4 Given a malicious document provided by an attacker, the OpenKM DMS is vulnerable to a stored (persistent, or "Type II")...
CVE-2022-46663HIGH7.5In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
CVE-2022-45768HIGH8.8Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker ...
CVE-2022-47412MEDIUM5.4Given a malicious document provided by an attacker, the ONLYOFFICE Workspace DMS is vulnerable to a stored (persistent, ...
CVE-2022-4883HIGH8.8A flaw was found in libXpm. When processing files with .Z or .gz extensions, the library calls external programs to comp...
CVE-2022-46285HIGH7.5A flaw was found in libXpm. This issue occurs when parsing a file with a comment not closed; the end-of-file condition w...
CVE-2022-24990HIGH7.5TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agen...
CVE-2022-41313MEDIUM5.4A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industri...
CVE-2022-41312MEDIUM5.4A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industri...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now