2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22330 | MEDIUM | 5.3 | 0.7% | Sep 13, 2022 | IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the H... |
| CVE-2022-22329 | MEDIUM | 4.3 | 0.5% | Sep 13, 2022 | IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be ab... |
| CVE-2022-3205 | MEDIUM | 6.1 | 0.4% | Sep 13, 2022 | Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project na... |
| CVE-2022-38342 | MEDIUM | 6.5 | 0.5% | Sep 13, 2022 | Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerab... |
| CVE-2022-32244 | MEDIUM | 5.2 | 0.5% | Sep 13, 2022 | Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retriev... |
| CVE-2022-20399 | MEDIUM | 5.5 | 0.1% | Sep 13, 2022 | In the SEPolicy configuration of system apps, there is a possible access to the 'ip' utility due to an insecure default ... |
| CVE-2022-20396 | MEDIUM | 5.5 | 0.1% | Sep 13, 2022 | In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or us... |
| CVE-2022-20393 | MEDIUM | 5.5 | 0.1% | Sep 13, 2022 | In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to an integer overf... |
| CVE-2022-39207 | MEDIUM | 5.4 | 0.7% | Sep 13, 2022 | Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save buil... |
| CVE-2022-38006 | MEDIUM | 6.5 | 1.8% | Sep 13, 2022 | Windows Graphics Component Information Disclosure Vulnerability |
| CVE-2022-37959 | MEDIUM | 6.5 | 1.8% | Sep 13, 2022 | Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability |
| CVE-2022-35837 | MEDIUM | 6.5 | 2.0% | Sep 13, 2022 | Windows Graphics Component Information Disclosure Vulnerability |
| CVE-2022-35832 | MEDIUM | 5.5 | 0.9% | Sep 13, 2022 | Windows Event Tracing Denial of Service Vulnerability |
| CVE-2022-35831 | MEDIUM | 5.5 | 0.7% | Sep 13, 2022 | Windows Remote Access Connection Manager Information Disclosure Vulnerability |
| CVE-2022-34728 | MEDIUM | 5.5 | 3.7% | Sep 13, 2022 | Windows Graphics Component Information Disclosure Vulnerability |
| CVE-2022-34723 | MEDIUM | 5.5 | 1.0% | Sep 13, 2022 | Windows DPAPI (Data Protection Application Programming Interface) Information Disclosure Vulnerability |
| CVE-2022-39202 | MEDIUM | 6.3 | 0.7% | Sep 13, 2022 | matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you... |
| CVE-2022-36108 | MEDIUM | 6.1 | 0.7% | Sep 13, 2022 | TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ... |
| CVE-2022-36107 | MEDIUM | 5.4 | 0.7% | Sep 13, 2022 | TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ... |
| CVE-2022-36106 | MEDIUM | 5.4 | 0.7% | Sep 13, 2022 | TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ... |
| CVE-2022-36105 | MEDIUM | 5.3 | 1.0% | Sep 13, 2022 | TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ... |
| CVE-2022-36020 | MEDIUM | 6.1 | 0.6% | Sep 13, 2022 | The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explic... |
| CVE-2022-39799 | MEDIUM | 6.1 | 0.4% | Sep 13, 2022 | An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpa... |
| CVE-2022-39014 | MEDIUM | 5.3 | 0.4% | Sep 13, 2022 | Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 4... |
| CVE-2022-35298 | MEDIUM | 6.1 | 0.4% | Sep 13, 2022 | SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now