2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29830CRITICAL9.1Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and M...
CVE-2022-29829HIGH7.5Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT De...
CVE-2022-29828HIGH7.5Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows...
CVE-2022-29827HIGH7.5Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows...
CVE-2022-29826HIGH7.5Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.087R...
CVE-2022-29825HIGH7.5Use of Hard-coded Password vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.090U, GT Designer3 V...
CVE-2022-25164HIGH7.5Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z...
CVE-2022-2650CRITICAL9.8Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.
CVE-2022-26885HIGH7.5When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to vers...
CVE-2022-4090HIGH8.8A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unkno...
CVE-2022-4089MEDIUM5.4A vulnerability was found in rickxy Stock Management System. It has been declared as problematic. This vulnerability aff...
CVE-2022-4088CRITICAL9.8A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some u...
CVE-2022-40977HIGH7.5A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker c...
CVE-2022-40976MEDIUM5.5A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a z...
CVE-2022-40266MEDIUM6.5Improper Input Validation vulnerability in Mitsubishi Electric GOT2000 Series GT27 model FTP server versions 01.39.000 a...
CVE-2022-4136CRITICAL9.8Dangerous method exposed which can lead to RCE in qmpass/leadshop v1.4.15 allows an attacker to control the target host ...
CVE-2022-44749HIGH7A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above c...
CVE-2022-44748HIGH7.5A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arb...
CVE-2022-45873MEDIUM5.5systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long back...
CVE-2022-45872CRITICAL9.8iTerm2 before 3.4.18 mishandles a DECRQSS response.
CVE-2022-45868HIGH7.8The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminP...
CVE-2022-45280MEDIUM5.4A cross-site scripting (XSS) vulnerability in the Url parameter in /login.php of EyouCMS v1.6.0 allows attackers to exec...
CVE-2022-45278HIGH8.8Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html...
CVE-2022-45276CRITICAL9.8An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated attackers to obtain the Admi...
CVE-2022-44789HIGH8.8A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to a...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now