2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-45913MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via one of attributes in webmail URLs to execut...
CVE-2022-45911MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur on the Classic UI login page by injecting arbit...
CVE-2022-44939HIGH7.8Efs Software Easy Chat Server Version 3.1 was discovered to contain a DLL hijacking vulnerability via the component Text...
CVE-2022-41613HIGH7.8Bentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to an Out-of-Bounds Read when when ...
CVE-2022-40201HIGH7.8Bentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to a Stack-Based Buffer Overflow wh...
CVE-2022-2484HIGH7.8 The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker...
CVE-2022-2483HIGH7.1 The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for fi...
CVE-2022-2482HIGH8.8 A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow a...
CVE-2022-47976HIGH7.5The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful ...
CVE-2022-47975HIGH7.5The DUBAI module has a double free vulnerability. Successful exploitation of this vulnerability may affect system availa...
CVE-2022-47974MEDIUM6.5The Bluetooth AVRCP module has a vulnerability that can lead to DoS attacks.Successful exploitation of this vulnerabilit...
CVE-2022-46762HIGH7.5The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect d...
CVE-2022-46761HIGH7.5The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this ...
CVE-2022-39073CRITICAL9.8There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an att...
CVE-2022-39072MEDIUM5.4There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input...
CVE-2022-44149HIGH8.8The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by...
CVE-2022-4879HIGH7.5A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vuln...
CVE-2022-4878MEDIUM5.3A vulnerability classified as critical has been found in JATOS. Affected is the function ZipUtil of the file modules/com...
CVE-2022-45935MEDIUM5.5Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to ac...
CVE-2022-45787MEDIUM5.5Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclo...
CVE-2022-25923CRITICAL9.8Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionali...
CVE-2022-42979HIGH8.8Information disclosure due to an insecure hostname validation in the RYDE application 5.8.43 for Android and iOS allows ...
CVE-2022-44870MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary w...
CVE-2022-40049HIGH7.5SQL injection vulnerability in sourcecodester Theme Park Ticketing System 1.0 allows remote attackers to view sensitive ...
CVE-2022-44541Rejected reason: CVE was unused by HPE.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now