2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-38337CRITICAL9.1When aborting a SFTP connection, MobaXterm before v22.1 sends a hardcoded password to the server. The server treats this...
CVE-2022-38336HIGH8.1An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP...
CVE-2022-46464Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-45990MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attacker...
CVE-2022-45769MEDIUM6.1A cross-site scripting (XSS) vulnerability in ClicShopping_V3 v3.402 allows attackers to execute arbitrary web scripts o...
CVE-2022-45020HIGH8.8Rukovoditel v3.2.1 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability in the component /ruko...
CVE-2022-45019HIGH7.5SLiMS 9 Bulian v9.5.0 was discovered to contain a SQL injection vulnerability via the keywords parameter.
CVE-2022-43706MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0 allowed logged in users wit...
CVE-2022-45912HIGH7.2An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUplo...
CVE-2022-43557MEDIUM5.3The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, th...
CVE-2022-43556MEDIUM6.1Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XSS in the text input field ...
CVE-2022-43553HIGH8.8A remote code execution vulnerability in EdgeRouters (Version 2.0.9-hotfix.4 and earlier) allows a malicious actor with ...
CVE-2022-43549CRITICAL9.8Improper authentication in Veeam Backup for Google Cloud v1.0 and v3.0 allows attackers to bypass authentication mechani...
CVE-2022-43548HIGH8.1A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insuffic...
CVE-2022-40259CRITICAL9.8MegaRAC Default Credentials Vulnerability
CVE-2022-40242CRITICAL9.8MegaRAC Default Credentials Vulnerability
CVE-2022-35260MEDIUM6.5curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white sp...
CVE-2022-35259HIGH7.8XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute...
CVE-2022-35258HIGH7.5An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in vers...
CVE-2022-35256MEDIUM6.5The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated wit...
CVE-2022-35255CRITICAL9.1A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretK...
CVE-2022-35254HIGH7.5An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in vers...
CVE-2022-32224CRITICAL9.8A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6....
CVE-2022-32221CRITICAL9.8When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data t...
CVE-2022-30123CRITICAL10A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now