2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-33323HIGH7.5Active Debug Code vulnerability in robot controller of Mitsubishi Electric Corporation industrial robot MELFA SD/SQ Seri...
CVE-2022-37034MEDIUM5.3In dotCMS 5.x-22.06, it is possible to call the TempResource multiple times, each time requesting the dotCMS server to d...
CVE-2022-47872HIGH8.8A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbit...
CVE-2022-45783MEDIUM6.5An issue was discovered in dotCMS core 4.x through 22.10.2. An authenticated directory traversal vulnerability in the do...
CVE-2022-45782HIGH8.8An issue was discovered in dotCMS core 5.3.8.5 through 5.3.8.15 and 21.03 through 22.10.1. A cryptographically insecure ...
CVE-2022-3913MEDIUM5.3Rapid7 Nexpose and InsightVM versions 6.6.82 through 6.6.177 fail to validate the certificate of the update server when ...
CVE-2022-37033MEDIUM6.5In dotCMS 5.x-22.06, TempFileAPI allows a user to create a temporary file based on a passed in URL, while attempting to ...
CVE-2022-3083MEDIUM5.4All versions of Landis+Gyr E850 (ZMQ200) are vulnerable to CWE-784: Reliance on Cookies Without Validation and Integrity...
CVE-2022-31364HIGH8.8Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Over...
CVE-2022-31363HIGH8.8Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Over...
CVE-2022-30904HIGH8.8In Bestechnic Bluetooth Mesh SDK (BES2300) V1.0, a buffer overflow vulnerability can be triggered during provisioning, b...
CVE-2022-46934MEDIUM6.1kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /control...
CVE-2022-47983MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2022-43922MEDIUM6.5IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, and 6.2 could disclose sensitive infor...
CVE-2022-4254HIGH8.8sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
CVE-2022-48094MEDIUM4.9lmxcms v1.41 was discovered to contain an arbitrary file read vulnerability via TemplateAction.class.php.
CVE-2022-48093HIGH7.2Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php...
CVE-2022-47717HIGH7.5Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).
CVE-2022-47715MEDIUM5.3In Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic.
CVE-2022-47714CRITICAL9.8Last Yard 22.09.8-1 does not enforce HSTS headers
CVE-2022-47003CRITICAL9.8A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a...
CVE-2022-47002CRITICAL9.8A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authenticatio...
CVE-2022-3990HIGH7.8HPSFViewer might allow Escalation of Privilege. This potential vulnerability was remediated on July 29th, 2022. Customer...
CVE-2022-27538HIGH7A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC produc...
CVE-2022-27537HIGH7.8Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now