2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-45598MEDIUM6.1Cross Site Scripting vulnerability in Joplin Desktop App before v2.9.17 allows attacker to execute arbitrary code via im...
CVE-2022-28331CRITICAL9.8On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sen...
CVE-2022-25147MEDIUM6.5Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allow...
CVE-2022-24963CRITICAL9.8Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker...
CVE-2022-46835HIGH7.5IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, Identity...
CVE-2022-45435MEDIUM6.5IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, Identity...
CVE-2022-44645HIGH8.8In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code...
CVE-2022-44644MEDIUM6.5In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could...
CVE-2022-39061MEDIUM6.5ChangingTech MegaServiSignAdapter component has a vulnerability of Out-of-bounds Read due to insufficient validation for...
CVE-2022-39060CRITICAL9.8ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote ...
CVE-2022-39059HIGH7.5ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unau...
CVE-2022-45789CRITICAL9.8A CWE-294: Authentication Bypass by Capture-replay vulnerability exists that could cause execution of unauthorized Modbu...
CVE-2022-25979MEDIUM6.1Versions of the package jsuites before 5.0.1 are vulnerable to Cross-site Scripting (XSS) due to improper user-input san...
CVE-2022-25881HIGH7.5This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request...
CVE-2022-21129CRITICAL9.8Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization ...
CVE-2022-4898MEDIUM5.4In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in t...
CVE-2022-4441HIGH8.8Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u...
CVE-2022-4041HIGH8.8Incorrect Privilege Assignment vulnerability in Hitachi Storage Plug-in for VMware vCenter allows remote authenticated u...
CVE-2022-44897MEDIUM6.1A cross-site scripting (XSS) vulnerability in ApolloTheme AP PageBuilder component through 2.4.4 allows attackers to exe...
CVE-2022-40258MEDIUM5.3AMI Megarac Weak password hashes for Redfish & API
CVE-2022-30421HIGH7.8Improper Authentication vulnerability in Toshiba Storage Security Software V1.2.0.7413 is that allows for sensitive info...
CVE-2022-48176HIGH7.8Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94...
CVE-2022-45897MEDIUM6.5On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtai...
CVE-2022-48175CRITICAL9.8Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/i...
CVE-2022-32748HIGH8.3A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now