2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-46160MEDIUM4.3Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14...
CVE-2022-41915MEDIUM6.5Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior ...
CVE-2022-23473MEDIUM4.3Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14...
CVE-2022-41275MEDIUM6.1In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link tha...
CVE-2022-41274MEDIUM6.5SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application ...
CVE-2022-41273MEDIUM6.1Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can...
CVE-2022-41272HIGH8.6An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Se...
CVE-2022-41271CRITICAL9.4An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Pr...
CVE-2022-41268HIGH7.5In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, ...
CVE-2022-41267HIGH8.8SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/repla...
CVE-2022-41266MEDIUM6.1Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2...
CVE-2022-41264HIGH8.8Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 7...
CVE-2022-45269HIGH7.5A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attacke...
CVE-2022-3931Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-41263MEDIUM4.3Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions...
CVE-2022-41262MEDIUM6.1Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenti...
CVE-2022-41261MEDIUM5.5SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a f...
CVE-2022-0925Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-46906MEDIUM5.4Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary H...
CVE-2022-46905MEDIUM6.1Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an unauthenticated attacker to inject arbitrary...
CVE-2022-46904MEDIUM5.4Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary H...
CVE-2022-46903MEDIUM5.4Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary H...
CVE-2022-45275HIGH7.2An arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing Sy...
CVE-2022-42716HIGH8.8An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make imp...
CVE-2022-4314CRITICAL9.8Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now