2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35295 | MEDIUM | 4.9 | 1.2% | Sep 13, 2022 | In SAP Host Agent (SAPOSCOL) - version 7.22, an attacker may use files created by saposcol to escalate privileges for th... |
| CVE-2022-35294 | MEDIUM | 5.4 | 0.4% | Sep 13, 2022 | An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Ser... |
| CVE-2022-3190 | MEDIUM | 5.5 | 1.7% | Sep 13, 2022 | Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denia... |
| CVE-2022-3027 | MEDIUM | 5.7 | 0.3% | Sep 13, 2022 | The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could... |
| CVE-2022-38453 | MEDIUM | 4.4 | 0.2% | Sep 13, 2022 | Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation se... |
| CVE-2022-38069 | MEDIUM | 6.1 | 0.3% | Sep 13, 2022 | Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with mom... |
| CVE-2022-36780 | MEDIUM | 5.3 | 0.4% | Sep 13, 2022 | Avdor CIS - crystal quality Credentials Management Errors. The product is phone call recorder, you can hear all the reco... |
| CVE-2022-36778 | MEDIUM | 5.4 | 0.4% | Sep 13, 2022 | insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this... |
| CVE-2022-36385 | MEDIUM | 6.8 | 0.4% | Sep 13, 2022 | A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resu... |
| CVE-2022-1602 | MEDIUM | 5.5 | 0.2% | Sep 13, 2022 | A potential security vulnerability has been identified in HP ThinPro 7.2 Service Pack 8 (SP8). The security vulnerabilit... |
| CVE-2022-3175 | MEDIUM | 5.3 | 0.7% | Sep 13, 2022 | Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2. |
| CVE-2022-39158 | MEDIUM | 5.3 | 1.2% | Sep 13, 2022 | A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i80... |
| CVE-2022-37302 | MEDIUM | 5.5 | 0.2% | Sep 13, 2022 | A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause... |
| CVE-2022-38299 | MEDIUM | 4.3 | 0.5% | Sep 12, 2022 | An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP int... |
| CVE-2022-38295 | MEDIUM | 6.1 | 1.0% | Sep 12, 2022 | Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. Thi... |
| CVE-2022-38291 | MEDIUM | 6.1 | 0.4% | Sep 12, 2022 | SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via ... |
| CVE-2022-38135 | MEDIUM | 4.3 | 0.5% | Sep 12, 2022 | Broken Access Control vulnerability in Dean Oakley's Photospace Gallery plugin <= 2.3.5 at WordPress allows users with s... |
| CVE-2022-39200 | MEDIUM | 5.3 | 0.3% | Sep 12, 2022 | Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the ... |
| CVE-2022-36101 | MEDIUM | 5.3 | 0.5% | Sep 12, 2022 | Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the bac... |
| CVE-2022-31225 | MEDIUM | 5.1 | 0.2% | Sep 12, 2022 | Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could poten... |
| CVE-2022-31222 | MEDIUM | 4.4 | 0.2% | Sep 12, 2022 | Dell BIOS versions contain a Missing Release of Resource after Effective Lifetime vulnerability. A local authenticated a... |
| CVE-2022-31220 | MEDIUM | 5.1 | 0.2% | Sep 12, 2022 | Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could poten... |
| CVE-2022-36254 | MEDIUM | 5.4 | 0.6% | Sep 12, 2022 | Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 all... |
| CVE-2022-34110 | MEDIUM | 5.5 | 0.3% | Sep 12, 2022 | An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files r... |
| CVE-2022-38972 | MEDIUM | 6.1 | 0.7% | Sep 12, 2022 | Cross-site scripting vulnerability in Movable Type plugin A-Form versions prior to 4.1.1 (for Movable Type 7 Series) and... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now