2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-22330MEDIUM5.3IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the H...
CVE-2022-22329MEDIUM4.3IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be ab...
CVE-2022-3205MEDIUM6.1Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project na...
CVE-2022-38342MEDIUM6.5Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerab...
CVE-2022-32244MEDIUM5.2Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retriev...
CVE-2022-20399MEDIUM5.5In the SEPolicy configuration of system apps, there is a possible access to the 'ip' utility due to an insecure default ...
CVE-2022-20396MEDIUM5.5In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or us...
CVE-2022-20393MEDIUM5.5In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to an integer overf...
CVE-2022-39207MEDIUM5.4Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save buil...
CVE-2022-38006MEDIUM6.5Windows Graphics Component Information Disclosure Vulnerability
CVE-2022-37959MEDIUM6.5Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability
CVE-2022-35837MEDIUM6.5Windows Graphics Component Information Disclosure Vulnerability
CVE-2022-35832MEDIUM5.5Windows Event Tracing Denial of Service Vulnerability
CVE-2022-35831MEDIUM5.5Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2022-34728MEDIUM5.5Windows Graphics Component Information Disclosure Vulnerability
CVE-2022-34723MEDIUM5.5Windows DPAPI (Data Protection Application Programming Interface) Information Disclosure Vulnerability
CVE-2022-39202MEDIUM6.3matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you...
CVE-2022-36108MEDIUM6.1TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ...
CVE-2022-36107MEDIUM5.4TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ...
CVE-2022-36106MEDIUM5.4TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ...
CVE-2022-36105MEDIUM5.3TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ...
CVE-2022-36020MEDIUM6.1The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explic...
CVE-2022-39799MEDIUM6.1An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpa...
CVE-2022-39014MEDIUM5.3Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 4...
CVE-2022-35298MEDIUM6.1SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now