2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-42285 | HIGH | 7.8 | 0.2% | Jan 13, 2023 | DGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged user can disable SP... |
| CVE-2022-42284 | MEDIUM | 5.5 | 0.1% | Jan 13, 2023 | NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credenti... |
| CVE-2022-42283 | HIGH | 7.8 | 0.2% | Jan 13, 2023 | NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause ... |
| CVE-2022-42282 | MEDIUM | 5.5 | 0.5% | Jan 13, 2023 | NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may ... |
| CVE-2022-42281 | MEDIUM | 6.7 | 0.2% | Jan 13, 2023 | NVIDIA DGX A100 contains a vulnerability in SBIOS in the FsRecovery, which may allow a highly privileged local attacker ... |
| CVE-2022-42280 | HIGH | 7.8 | 0.3% | Jan 13, 2023 | NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path travers... |
| CVE-2022-42279 | HIGH | 8.8 | 1.1% | Jan 13, 2023 | NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, w... |
| CVE-2022-42278 | HIGH | 7.8 | 0.6% | Jan 13, 2023 | NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can read and write to arbitrary locati... |
| CVE-2022-42277 | HIGH | 8.2 | 0.2% | Jan 13, 2023 | NVIDIA DGX Station contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can re... |
| CVE-2022-42276 | HIGH | 8.2 | 0.2% | Jan 13, 2023 | NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read,... |
| CVE-2022-48258 | MEDIUM | 5.3 | 1.1% | Jan 13, 2023 | In Eternal Terminal 6.2.1, etserver and etclient have world-readable logfiles. |
| CVE-2022-48257 | MEDIUM | 5.3 | 0.9% | Jan 13, 2023 | In Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp. |
| CVE-2022-48256 | HIGH | 7.5 | 0.7% | Jan 13, 2023 | Technitium DNS Server before 10.0 allows a self-CNAME denial-of-service attack in which a CNAME loop causes an answer to... |
| CVE-2022-46478 | CRITICAL | 9.8 | 1.1% | Jan 13, 2023 | The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attacke... |
| CVE-2022-46471 | CRITICAL | 9.8 | 0.8% | Jan 13, 2023 | Online Health Care System v1.0 was discovered to contain a SQL injection vulnerability via the consulting_id parameter a... |
| CVE-2022-42275 | HIGH | 7.1 | 0.2% | Jan 13, 2023 | NVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. Th... |
| CVE-2022-42274 | HIGH | 7.8 | 0.3% | Jan 13, 2023 | NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause ... |
| CVE-2022-3161 | HIGH | 7.8 | 0.4% | Jan 13, 2023 | The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF files. This could allow ... |
| CVE-2022-3160 | HIGH | 7.8 | 0.4% | Jan 13, 2023 | The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted ... |
| CVE-2022-3159 | HIGH | 7.8 | 0.5% | Jan 13, 2023 | The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially craf... |
| CVE-2022-4616 | CRITICAL | 9.1 | 4.8% | Jan 13, 2023 | The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis ... |
| CVE-2022-46463 | HIGH | 7.5 | 6.2% | Jan 13, 2023 | An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories with... |
| CVE-2022-46438 | MEDIUM | 5.4 | 0.4% | Jan 13, 2023 | A cross-site scripting (XSS) vulnerability in the /admin/article_category.php component of DouPHP v1.7 20221118 allows a... |
| CVE-2022-42704 | MEDIUM | 5.4 | 0.4% | Jan 13, 2023 | A cross-site scripting (XSS) vulnerability in Employee Service Center (esc) and Service Portal (sp) in ServiceNow Quebec... |
| CVE-2022-41778 | HIGH | 8.8 | 1.0% | Jan 13, 2023 | Delta Electronics InfraSuite Device Master versions 00.00.01a and prior deserialize user-supplied data provided through... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now