2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-25820MEDIUM4.6A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perfo...
CVE-2022-25819MEDIUM5.5OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memor...
CVE-2022-25816MEDIUM4.6Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change ...
CVE-2022-25368MEDIUM4.7Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to...
CVE-2022-25244MEDIUM6.5Vault Enterprise clusters using the tokenization transform feature can expose the tokenization key through the tokenizat...
CVE-2022-25243MEDIUM6.5"Vault and Vault Enterprise 1.8.0 through 1.8.8, and 1.9.3 allowed the PKI secrets engine under certain configurations t...
CVE-2022-25215MEDIUM5.3Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove)...
CVE-2022-25213MEDIUM6.8Improper physical access control and use of hard-coded credentials in /etc/passwd permits an attacker with physical acce...
CVE-2022-25108MEDIUM5.5Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer dereference during PDF parsi...
CVE-2022-24932MEDIUM4.6Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physi...
CVE-2022-24608MEDIUM6.1Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc/function.php.
CVE-2022-24432MEDIUM5.4Persistent cross-site scripting (XSS) in the web interface of ipDIO allows an authenticated remote attacker to introduce...
CVE-2022-24399MEDIUM6.1The SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not sufficiently sanitize the input na...
CVE-2022-24398MEDIUM6.5Under certain conditions SAP Business Objects Business Intelligence Platform - versions 420, 430, allows an authenticate...
CVE-2022-24397MEDIUM6.1SAP NetWeaver Enterprise Portal - versions 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, ...
CVE-2022-24395MEDIUM6.1SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-c...
CVE-2022-24177MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component cgi-bin/ej.cgi of Ex libris ALEPH 500 v18.1 and v20 allows a...
CVE-2022-22835MEDIUM6.5An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL ...
CVE-2022-21158MEDIUM5.4A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (...
CVE-2022-21146MEDIUM6.1Persistent cross-site scripting in the web interface of ipDIO allows an unauthenticated remote attacker to introduce arb...
CVE-2022-21132MEDIUM6.5Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfS...
CVE-2022-20060MEDIUM6.6In preloader (usb), there is a possible permission bypass due to a missing proper image authentication. This could lead ...
CVE-2022-20059MEDIUM6.6In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca...
CVE-2022-20058MEDIUM6.6In preloader (usb), there is a possible out of bounds write due to a missing bounds check. This could lead to local esca...
CVE-2022-20057MEDIUM6.5In btif, there is a possible memory corruption due to incorrect error handling. This could lead to local escalation of p...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now