2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-46160 | MEDIUM | 4.3 | 0.5% | Dec 13, 2022 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14... |
| CVE-2022-41915 | MEDIUM | 6.5 | 0.9% | Dec 13, 2022 | Netty project is an event-driven asynchronous network application framework. Starting in version 4.1.83.Final and prior ... |
| CVE-2022-23473 | MEDIUM | 4.3 | 0.5% | Dec 13, 2022 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. In versions prior to 14... |
| CVE-2022-41275 | MEDIUM | 6.1 | 0.5% | Dec 13, 2022 | In SAP Solution Manager (Enterprise Search) - versions 740, and 750, an unauthenticated attacker can generate a link tha... |
| CVE-2022-41274 | MEDIUM | 6.5 | 0.6% | Dec 13, 2022 | SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application ... |
| CVE-2022-41273 | MEDIUM | 6.1 | 0.5% | Dec 13, 2022 | Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can... |
| CVE-2022-41272 | HIGH | 8.6 | 1.0% | Dec 13, 2022 | An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Se... |
| CVE-2022-41271 | CRITICAL | 9.4 | 0.6% | Dec 13, 2022 | An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging System of SAP NetWeaver Pr... |
| CVE-2022-41268 | HIGH | 7.5 | 0.6% | Dec 13, 2022 | In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, ... |
| CVE-2022-41267 | HIGH | 8.8 | 0.8% | Dec 13, 2022 | SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/repla... |
| CVE-2022-41266 | MEDIUM | 6.1 | 0.4% | Dec 13, 2022 | Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2... |
| CVE-2022-41264 | HIGH | 8.8 | 0.9% | Dec 13, 2022 | Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 7... |
| CVE-2022-45269 | HIGH | 7.5 | 3.1% | Dec 12, 2022 | A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attacke... |
| CVE-2022-3931 | — | — | — | Dec 12, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-41263 | MEDIUM | 4.3 | 0.2% | Dec 12, 2022 | Due to a missing authentication check, SAP Business Objects Business Intelligence Platform (Web Intelligence) - versions... |
| CVE-2022-41262 | MEDIUM | 6.1 | 0.4% | Dec 12, 2022 | Due to insufficient input validation, SAP NetWeaver AS Java (HTTP Provider Service) - version 7.50, allows an unauthenti... |
| CVE-2022-41261 | MEDIUM | 5.5 | 0.2% | Dec 12, 2022 | SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a f... |
| CVE-2022-0925 | — | — | — | Dec 12, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-46906 | MEDIUM | 5.4 | 0.3% | Dec 12, 2022 | Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary H... |
| CVE-2022-46905 | MEDIUM | 6.1 | 0.4% | Dec 12, 2022 | Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an unauthenticated attacker to inject arbitrary... |
| CVE-2022-46904 | MEDIUM | 5.4 | 0.3% | Dec 12, 2022 | Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary H... |
| CVE-2022-46903 | MEDIUM | 5.4 | 0.3% | Dec 12, 2022 | Insufficient processing of user input in WebSoft HCM 2021.2.3.327 allows an authenticated attacker to inject arbitrary H... |
| CVE-2022-45275 | HIGH | 7.2 | 15.3% | Dec 12, 2022 | An arbitrary file upload vulnerability in /queuing/admin/ajax.php?action=save_settings of Dynamic Transaction Queuing Sy... |
| CVE-2022-42716 | HIGH | 8.8 | 1.3% | Dec 12, 2022 | An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make imp... |
| CVE-2022-4314 | CRITICAL | 9.8 | 0.8% | Dec 12, 2022 | Improper Privilege Management in GitHub repository ikus060/rdiffweb prior to 2.5.2. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now