2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-42285HIGH7.8DGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged user can disable SP...
CVE-2022-42284MEDIUM5.5NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credenti...
CVE-2022-42283HIGH7.8NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause ...
CVE-2022-42282MEDIUM5.5NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may ...
CVE-2022-42281MEDIUM6.7NVIDIA DGX A100 contains a vulnerability in SBIOS in the FsRecovery, which may allow a highly privileged local attacker ...
CVE-2022-42280HIGH7.8NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path travers...
CVE-2022-42279HIGH8.8NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, w...
CVE-2022-42278HIGH7.8NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can read and write to arbitrary locati...
CVE-2022-42277HIGH8.2NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can re...
CVE-2022-42276HIGH8.2NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read,...
CVE-2022-48258MEDIUM5.3In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles.
CVE-2022-48257MEDIUM5.3In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.
CVE-2022-48256HIGH7.5Technitium DNS Server before 10.0 allows a self-CNAME denial-of-service attack in which a CNAME loop causes an answer to...
CVE-2022-46478CRITICAL9.8The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attacke...
CVE-2022-46471CRITICAL9.8Online Health Care System v1.0 was discovered to contain a SQL injection vulnerability via the consulting_id parameter a...
CVE-2022-42275HIGH7.1NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. Th...
CVE-2022-42274HIGH7.8NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause ...
CVE-2022-3161HIGH7.8 The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF files. This could allow ...
CVE-2022-3160HIGH7.8 The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted ...
CVE-2022-3159HIGH7.8The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially craf...
CVE-2022-4616CRITICAL9.1The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis ...
CVE-2022-46463HIGH7.5An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories with...
CVE-2022-46438MEDIUM5.4A cross-site scripting (XSS) vulnerability in the /admin/article_category.php component of DouPHP v1.7 20221118 allows a...
CVE-2022-42704MEDIUM5.4A cross-site scripting (XSS) vulnerability in Employee Service Center (esc) and Service Portal (sp) in ServiceNow Quebec...
CVE-2022-41778HIGH8.8 Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now