2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4731MEDIUM5.4A vulnerability, which was classified as problematic, was found in myapnea up to 29.0.x. Affected is an unknown function...
CVE-2022-42898HIGH8.8PAC parsing in MIT Kerberos 5 (aka krb5) before 1.19.4 and 1.20.x before 1.20.1 has integer overflows that may lead to r...
CVE-2022-45896CRITICAL9.8Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upl...
CVE-2022-45895MEDIUM6.5Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code...
CVE-2022-45894MEDIUM6.5GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.
CVE-2022-45893HIGH8.8Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user ...
CVE-2022-45197HIGH7.5Slixmpp before 1.8.3 lacks SSL Certificate hostname validation in XMLStream, allowing an attacker to pose as any server ...
CVE-2022-44640CRITICAL9.8Heimdal before 7.7.1 allows remote attackers to execute arbitrary code because of an invalid free in the ASN.1 codec use...
CVE-2022-44381MEDIUM5.3Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /pas...
CVE-2022-44380MEDIUM5.4Snipe-IT before 6.0.14 is vulnerable to Cross Site Scripting (XSS) for View Assigned Assets.
CVE-2022-44017HIGH7.5An issue was discovered in Simmeth Lieferantenmanager before 5.6. Due to errors in session management, an attacker can l...
CVE-2022-44016HIGH7.5An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can download arbitrary files from the web ...
CVE-2022-44015CRITICAL9.8An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating ...
CVE-2022-44014MEDIUM6.5An issue was discovered in Simmeth Lieferantenmanager before 5.6. In the design of the API, a user is inherently able to...
CVE-2022-44013CRITICAL9.1An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can make various API calls without authent...
CVE-2022-44012MEDIUM5.4An issue was discovered in /DS/LM_API/api/SelectionService/InsertQueryWithActiveRelationsReturnId in Simmeth Lieferanten...
CVE-2022-42953HIGH7.5Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct r...
CVE-2022-45892MEDIUM5.4In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Searc...
CVE-2022-45891CRITICAL9.1Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upl...
CVE-2022-45890MEDIUM6.1In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter...
CVE-2022-45889HIGH7.2Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records ...
CVE-2022-47949CRITICAL9.8The Nintendo NetworkBuffer class, as used in Animal Crossing: New Horizons before 2.0.6 and other products, allows remot...
CVE-2022-47934MEDIUM6.5Brave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a c...
CVE-2022-47933MEDIUM6.5Brave Browser before 1.42.51 allowed a remote attacker to cause a denial of service via a crafted HTML file that referen...
CVE-2022-47932MEDIUM6.5Brave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mention...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now