2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-28770MEDIUM6.1Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated a...
CVE-2022-28216MEDIUM6.1SAP BusinessObjects Business Intelligence Platform (BI Workspace) - version 420, is susceptible to a Cross-Site Scriptin...
CVE-2022-28215MEDIUM4.7SAP NetWeaver ABAP Server and ABAP Platform - versions 740, 750, 787, allows an unauthenticated attacker to redirect use...
CVE-2022-27671MEDIUM6.5A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.
CVE-2022-27670MEDIUM6.5SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywh...
CVE-2022-27655MEDIUM6.5When a user opens a manipulated Universal 3D (.u3d, 3difr.x3d) received from untrusted sources in SAP 3D Visual Enterpri...
CVE-2022-27654MEDIUM6.5When a user opens a manipulated Photoshop Document (.psd, 2d.x3d) received from untrusted sources in SAP 3D Visual Enter...
CVE-2022-26109MEDIUM6.5When a user opens a manipulated Portable Document Format (.pdf, PDFView.x3d) received from untrusted sources in SAP 3D V...
CVE-2022-26108MEDIUM6.5When a user opens a manipulated Picture Exchange (.pcx, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterpr...
CVE-2022-26107MEDIUM6.5When a user opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) received from untrusted sources in SAP 3D Visual...
CVE-2022-26106MEDIUM6.5When a user opens a manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) received from untrusted sources in SAP 3D...
CVE-2022-26105MEDIUM6.1SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution ...
CVE-2022-23702MEDIUM6.7A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 Servers. The vulnera...
CVE-2022-22541MEDIUM6.5SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information...
CVE-2022-21202MEDIUM5.5The affected product is vulnerable to an out-of-bounds read, which may result in disclosure of sensitive information.
CVE-2022-21168MEDIUM5.5The affected product is vulnerable due to an invalid pointer initialization, which may lead to information disclosure.
CVE-2022-24248MEDIUM6.5RiteCMS version 3.1.0 and below suffers from an arbitrary file deletion via path traversal vulnerability in Admin Panel....
CVE-2022-24247MEDIUM6.5RiteCMS version 3.1.0 and below suffers from an arbitrary file overwrite via path traversal vulnerability in Admin Panel...
CVE-2022-0878MEDIUM6.5Electric Vehicle (EV) commonly utilises the Combined Charging System (CCS) for DC rapid charging. To exchange important ...
CVE-2022-0140MEDIUM5.3The Visual Form Builder WordPress plugin before 3.0.6 does not perform access control on entry form export, allowing una...
CVE-2022-28662MEDIUM6.5A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.2). The affected application contains an ...
CVE-2022-28329MEDIUM6.5A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versi...
CVE-2022-27481MEDIUM5.3A vulnerability has been identified in SCALANCE W1788-1 M12 (All versions < V3.0.0), SCALANCE W1788-2 EEC M12 (All versi...
CVE-2022-25756MEDIUM6.1A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 E...
CVE-2022-25650MEDIUM6.5A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.27), Mendix Applications...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now