2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-46095MEDIUM6.1Sourcecodester Covid-19 Directory on Vaccination System 1.0 was discovered to contain a Cross-Site Scripting (XSS) vulne...
CVE-2022-36222HIGH8.4Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5...
CVE-2022-36221MEDIUM6.5Nokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vulnerability which allows attackers to rea...
CVE-2022-4630MEDIUM5.3Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master.
CVE-2022-40841MEDIUM6.1A cross-site scripting (XSS) vulnerability in NdkAdvancedCustomizationFields v3.5.0 allows attackers to execute arbitrar...
CVE-2022-4287HIGH8.8Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager  2022.3.26 and earlier on ...
CVE-2022-47581HIGH7.5Isode M-Vault 16.0v0 through 17.x before 17.0v24 can crash upon an LDAP v1 bind request.
CVE-2022-44756MEDIUM6.5Insights for Vulnerability Remediation (IVR) is vulnerable to improper input validation. This may lead to information d...
CVE-2022-42454MEDIUM5.3Insights for Vulnerability Remediation (IVR) is vulnerable to man-in-the-middle attacks that may lead to information dis...
CVE-2022-38655MEDIUM5.8BigFix WebUI non-master operators are missing controls that prevent them from being able to modify the relevance of fixl...
CVE-2022-40145CRITICAL9.8This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the ...
CVE-2022-38065HIGH8.8A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and pri...
CVE-2022-38060HIGH8.8A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A miscon...
CVE-2022-46662MEDIUM6.7Roxio Creator LJB starts another program with an unquoted file path. Since a registered Windows service path contains sp...
CVE-2022-46330HIGH7.8Squirrel.Windows is both a toolset and a library that provides installation and update functionality for Windows desktop...
CVE-2022-46282HIGH7.8Use after free vulnerability in CX-Drive V3.00 and earlier allows a local attacker to execute arbitrary code by having a...
CVE-2022-44449MEDIUM4.8Stored cross-site scripting vulnerability in Zenphoto versions prior to 1.6 allows remote a remote authenticated attacke...
CVE-2022-43543MEDIUM5.4KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability caused by improper handlin...
CVE-2022-47635CRITICAL9.8Wildix WMS 6 before 6.02.20221216, WMS 5 before 5.04.20221214, and WMS4 before 4.04.45396.23 allows Server-side request ...
CVE-2022-25929MEDIUM5.4The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user inp...
CVE-2022-25895HIGH7.5All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sand...
CVE-2022-25893CRITICAL9.8The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the We...
CVE-2022-24431CRITICAL9.8All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper ...
CVE-2022-38546CRITICAL9.8A DNS misconfiguration was found in Zyxel NBG7510 firmware versions prior to V1.00(ABZY.3)C0, which could allow an unaut...
CVE-2022-4617MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.3.2.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now