2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-35295MEDIUM4.9In SAP Host Agent (SAPOSCOL) - version 7.22, an attacker may use files created by saposcol to escalate privileges for th...
CVE-2022-35294MEDIUM5.4An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Ser...
CVE-2022-3190MEDIUM5.5Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denia...
CVE-2022-3027MEDIUM5.7The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could...
CVE-2022-38453MEDIUM4.4Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation se...
CVE-2022-38069MEDIUM6.1Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with mom...
CVE-2022-36780MEDIUM5.3Avdor CIS - crystal quality Credentials Management Errors. The product is phone call recorder, you can hear all the reco...
CVE-2022-36778MEDIUM5.4insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this...
CVE-2022-36385MEDIUM6.8A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resu...
CVE-2022-1602MEDIUM5.5A potential security vulnerability has been identified in HP ThinPro 7.2 Service Pack 8 (SP8). The security vulnerabilit...
CVE-2022-3175MEDIUM5.3Missing Custom Error Page in GitHub repository ikus060/rdiffweb prior to 2.4.2.
CVE-2022-39158MEDIUM5.3A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i80...
CVE-2022-37302MEDIUM5.5A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause...
CVE-2022-38299MEDIUM4.3An issue in the Elasticsearch plugin of Appsmith v1.7.11 allows attackers to connect disallowed hosts to the AWS/GCP int...
CVE-2022-38295MEDIUM6.1Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. Thi...
CVE-2022-38291MEDIUM6.1SLiMS Senayan Library Management System v9.4.2 was discovered to contain a cross-site scripting (XSS) vulnerability via ...
CVE-2022-38135MEDIUM4.3Broken Access Control vulnerability in Dean Oakley's Photospace Gallery plugin <= 2.3.5 at WordPress allows users with s...
CVE-2022-39200MEDIUM5.3Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the ...
CVE-2022-36101MEDIUM5.3Shopware is an open source e-commerce software. In affected versions the request for the customer detail view in the bac...
CVE-2022-31225MEDIUM5.1Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could poten...
CVE-2022-31222MEDIUM4.4Dell BIOS versions contain a Missing Release of Resource after Effective Lifetime vulnerability. A local authenticated a...
CVE-2022-31220MEDIUM5.1Dell BIOS versions contain an Unchecked Return Value vulnerability. A local authenticated administrator user could poten...
CVE-2022-36254MEDIUM5.4Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 all...
CVE-2022-34110MEDIUM5.5An issue in Micro-Star International MSI Feature Navigator v1.0.1808.0901 allows attackers to download arbitrary files r...
CVE-2022-38972MEDIUM6.1Cross-site scripting vulnerability in Movable Type plugin A-Form versions prior to 4.1.1 (for Movable Type 7 Series) and...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now