2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24119CRITICAL9.8Certain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device...
CVE-2022-24118CRITICAL9.1Certain General Electric Renewable Energy products allow attackers to use a code to trigger a reboot into the factory de...
CVE-2022-24117CRITICAL9.8Certain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and i...
CVE-2022-24116CRITICAL9.8Certain General Electric Renewable Energy products have inadequate encryption strength. This affects iNET and iNET II be...
CVE-2022-37310MEDIUM6.1OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#...
CVE-2022-37309MEDIUM6.1OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
CVE-2022-29853MEDIUM5.4OX App Suite through 8.2 allows XSS via a certain complex hierarchy that forces use of Show Entire Message for a huge HT...
CVE-2022-29852MEDIUM5.4OX App Suite through 8.2 allows XSS because BMFreehand10 and image/x-freehand are not blocked.
CVE-2022-37308MEDIUM6.1OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.
CVE-2022-37313MEDIUM5.3OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA ...
CVE-2022-37312MEDIUM5.3OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to ...
CVE-2022-37311MEDIUM5.3OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect...
CVE-2022-37307MEDIUM6.1OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG...
CVE-2022-31469MEDIUM6.1OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ UR...
CVE-2022-4741MEDIUM6.5A vulnerability was found in docconv up to 1.2.0 and classified as problematic. This issue affects the function ConvertD...
CVE-2022-4740MEDIUM6.1A vulnerability, which was classified as problematic, has been found in kkFileView. Affected by this issue is the functi...
CVE-2022-4739CRITICAL9.8A vulnerability classified as critical was found in SourceCodester School Dormitory Management System 1.0. Affected by t...
CVE-2022-4738MEDIUM6.1A vulnerability classified as problematic has been found in SourceCodester Blood Bank Management System 1.0. Affected is...
CVE-2022-4737CRITICAL9.8A vulnerability was found in SourceCodester Blood Bank Management System 1.0. It has been rated as critical. This issue ...
CVE-2022-4736MEDIUM6.1A vulnerability was found in Venganzas del Pasado and classified as problematic. Affected by this issue is some unknown ...
CVE-2022-41318HIGH8.6A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection,...
CVE-2022-41317MEDIUM6.5An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, ...
CVE-2022-40005HIGH8.8Intelbras WiFiber 120AC inMesh before 1-1-220826 allows command injection by authenticated users, as demonstrated by the...
CVE-2022-37706HIGH7.8enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th...
CVE-2022-4735MEDIUM6.1A vulnerability classified as problematic was found in asrashley dash-live. This vulnerability affects the function read...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now