2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-39186MEDIUM5.5EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions
CVE-2022-39185CRITICAL9.8EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user...
CVE-2022-39184CRITICAL9.8EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication...
CVE-2022-39183MEDIUM6.1Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.
CVE-2022-39182HIGH8.8H C Mingham-Smith Ltd - Tardis 2000 Privilege escalation.Version 1.6 is vulnerable to privilege escalation which may all...
CVE-2022-46503MEDIUM5.4A cross-site scripting (XSS) vulnerability in the component /admin/register.php of Online Student Enrollment System v1.0...
CVE-2022-3592MEDIUM6.5A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' esca...
CVE-2022-3515CRITICAL9.8A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can...
CVE-2022-3437MEDIUM6.5A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines ...
CVE-2022-3341MEDIUM5.3A null pointer dereference issue was discovered in 'FFmpeg' in decode_main_header() function of libavformat/nutdec.c fil...
CVE-2022-2155HIGH7.1 A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access contro...
CVE-2022-47927MEDIUM5.5An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When ...
CVE-2022-24913MEDIUM5.5Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the...
CVE-2022-4365MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions start...
CVE-2022-4345MEDIUM6.5Infinite loops in the BPv6, OpenFlow, and Kafka protocol dissectors in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allow...
CVE-2022-4342LOW3.8An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.1 before 15.5.7, all versions start...
CVE-2022-4167HIGH7.5Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and ...
CVE-2022-4131MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions start...
CVE-2022-4037HIGH8.5An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 befor...
CVE-2022-3870MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.0 before 15.5.7, all versions start...
CVE-2022-3613HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 befor...
CVE-2022-3573MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions start...
CVE-2022-3514MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starti...
CVE-2022-4344MEDIUM4.3Memory exhaustion in the Kafka protocol dissector in Wireshark 4.0.0 to 4.0.1 and 3.6.0 to 3.6.9 allows denial of servic...
CVE-2022-4874HIGH7.5Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access conte...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now