2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4861MEDIUM4.9Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to...
CVE-2022-4860CRITICAL9.8A vulnerability was found in KBase Metrics. It has been classified as critical. This affects the function upload_user_da...
CVE-2022-4859MEDIUM6.1A vulnerability, which was classified as problematic, has been found in Joget up to 7.0.33. This issue affects the funct...
CVE-2022-4858HIGH7.5Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive...
CVE-2022-44621CRITICAL9.8Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.
CVE-2022-43396HIGH8.8In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed....
CVE-2022-4857HIGH7.8A vulnerability was found in Modbus Tools Modbus Poll up to 9.10.0 and classified as critical. Affected by this issue is...
CVE-2022-4856HIGH7.8A vulnerability has been found in Modbus Tools Modbus Slave up to 7.5.1 and classified as critical. Affected by this vul...
CVE-2022-4855CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Lead Management System 1.0. Affected is a...
CVE-2022-48196CRITICAL9.8Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects RAX40 before 1.0....
CVE-2022-48194HIGH8.8TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a De...
CVE-2022-44137HIGH7.2SourceCodester Sanitization Management System 1.0 is vulnerable to SQL Injection.
CVE-2022-36437CRITICAL9.1The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate ...
CVE-2022-30519MEDIUM6.1XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary c...
CVE-2022-38212HIGH7.5Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8...
CVE-2022-38211HIGH7.5Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.9...
CVE-2022-38210MEDIUM6.1There is a reflected HTML injection vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below that may allow a r...
CVE-2022-38209MEDIUM6.1There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote, una...
CVE-2022-38208MEDIUM6.1There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11 and below that may allow a remote, unauthent...
CVE-2022-38207MEDIUM6.1There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote rem...
CVE-2022-38206MEDIUM6.1There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 and below which may allow a remote remo...
CVE-2022-38205HIGH7.5In some non-default installations of Esri Portal for ArcGIS versions 10.9.1 and below, a directory traversal issue may a...
CVE-2022-38204MEDIUM6.1There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and 10.7.1 which may allow a remote, un...
CVE-2022-38203HIGH7.5Protections against potential Server-Side Request Forgery (SSRF) vulnerabilities in Esri Portal for ArcGIS versions 10.8...
CVE-2022-46181MEDIUM5.4Gotify server is a simple server for sending and receiving messages in real-time per WebSocket. Versions prior to 2.2.2 ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now