2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-43333CRITICAL9.8Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the...
CVE-2022-35120HIGH8.8IXPdata EasyInstall 6.6.14725 contains an access control issue.
CVE-2022-42718HIGH7.8Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authen...
CVE-2022-41971MEDIUM6.5Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, a...
CVE-2022-41970MEDIUM5.3Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares ...
CVE-2022-41969LOW2.7Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.11, 24.0.7, and 25.0.0, there is no pas...
CVE-2022-41968MEDIUM5.3Nextcloud Server is an open source personal cloud server. Prior to versions 23.0.10 and 24.0.5, calendar name lengths ar...
CVE-2022-23737MEDIUM6.5An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improp...
CVE-2022-43901MEDIUM5.5 IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.3 could disclose sensitive information. An authenticate...
CVE-2022-43900MEDIUM6.5 IBM WebSphere Automation for IBM Cloud Pak for Watson AIOps 1.4.2 could provide a weaker than expected security. A loca...
CVE-2022-41297MEDIUM6.5IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou...
CVE-2022-3713HIGH8.8A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall relea...
CVE-2022-3711MEDIUM4.3A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in ...
CVE-2022-3710LOW2.7A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database conten...
CVE-2022-3709HIGH8.4A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sopho...
CVE-2022-3696HIGH7.2A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older tha...
CVE-2022-3226HIGH7.2An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall...
CVE-2022-2969HIGH7.5Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname int...
CVE-2022-29837HIGH7.8A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which c...
CVE-2022-4257CRITICAL9.8A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknow...
CVE-2022-37017HIGH7.5Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Contr...
CVE-2022-37016CRITICAL9.8Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type...
CVE-2022-30528CRITICAL9.8SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attacke...
CVE-2022-28607HIGH7.5An issue was discovered in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers t...
CVE-2022-3270CRITICAL9.8In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which c...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now