2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-0002MEDIUM6.5Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to...
CVE-2022-0001MEDIUM6.5Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authoriz...
CVE-2022-0932MEDIUM6.5Missing Authorization in GitHub repository saleor/saleor prior to 3.1.2.
CVE-2022-0928MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.12.
CVE-2022-0870MEDIUM5.3Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.5.
CVE-2022-0912MEDIUM4.8Unrestricted Upload of File with Dangerous Type in GitHub repository microweber/microweber prior to 1.2.11.
CVE-2022-26878MEDIUM5.5drivers/bluetooth/virtio_bt.c in the Linux kernel before 5.16.3 has a memory leak (socket buffers have memory allocated ...
CVE-2022-26874MEDIUM5.4lib/Horde/Mime/Viewer/Ooo.php in Horde Mime_Viewer before 2.2.4 allows XSS via an OpenOffice document, leading to accoun...
CVE-2022-0822MEDIUM5.4Cross-site Scripting (XSS) - Reflected in GitHub repository orchardcms/orchardcore prior to 1.3.0.
CVE-2022-25511MEDIUM6.5An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place ...
CVE-2022-25507MEDIUM5.4FreeTAKServer-UI v1.9.8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Callsign par...
CVE-2022-25506MEDIUM6.5FreeTAKServer-UI v1.9.8 was discovered to contain a SQL injection vulnerability via the API endpoint /AuthenticateUser.
CVE-2022-0821MEDIUM6.5Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.
CVE-2022-0820MEDIUM6.1Cross-site Scripting (XSS) - Stored in GitHub repository orchardcms/orchardcore prior to 1.3.0.
CVE-2022-26847MEDIUM5.3SPIP before 3.2.14 and 4.x before 4.0.5 allows unauthenticated access to information about editorial objects.
CVE-2022-26778MEDIUM6.5Veritas System Recovery (VSR) 18 and 21 stores a network destination password in the Windows registry during configurati...
CVE-2022-26661MEDIUM6.5An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x an...
CVE-2022-26652MEDIUM6.5NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStre...
CVE-2022-26355MEDIUM4.4Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a regist...
CVE-2022-26104MEDIUM5.3SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messag...
CVE-2022-26103MEDIUM5.3Under certain conditions, SAP NetWeaver (Real Time Messaging Framework) - version 7.50, allows an attacker to access inf...
CVE-2022-26102MEDIUM5.4Due to missing authorization check, SAP NetWeaver Application Server for ABAP - versions 700, 701, 702, 731, allows an a...
CVE-2022-26101MEDIUM6.1Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs, resulting in Cross-Site S...
CVE-2022-25825MEDIUM5.5Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the aut...
CVE-2022-25822MEDIUM6.2An use after free vulnerability in sdp driver prior to SMR Mar-2022 Release 1 allows kernel crash.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now