2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23049 | MEDIUM | 5.4 | 3.0% | Feb 9, 2022 | Exponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header wh... |
| CVE-2022-23047 | MEDIUM | 4.8 | 2.9% | Feb 9, 2022 | Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organi... |
| CVE-2022-22812 | MEDIUM | 6.1 | 0.6% | Feb 9, 2022 | A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that... |
| CVE-2022-22809 | MEDIUM | 5.3 | 0.8% | Feb 9, 2022 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch... |
| CVE-2022-22780 | MEDIUM | 6.5 | 1.7% | Feb 9, 2022 | The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions... |
| CVE-2022-22546 | MEDIUM | 5.4 | 0.5% | Feb 9, 2022 | Due to improper HTML encoding in input control summary, an authorized attacker can execute XSS vulnerability in SAP Busi... |
| CVE-2022-22545 | MEDIUM | 4.9 | 0.8% | Feb 9, 2022 | A high privileged user who has access to transaction SM59 can read connection details stored with the destination for ht... |
| CVE-2022-22542 | MEDIUM | 6.5 | 1.0% | Feb 9, 2022 | S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Ro... |
| CVE-2022-22539 | MEDIUM | 6.5 | 1.0% | Feb 9, 2022 | When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterpr... |
| CVE-2022-22538 | MEDIUM | 6.5 | 1.0% | Feb 9, 2022 | When a user opens a manipulated Adobe Illustrator file format (.ai, ai.x3d) received from untrusted sources in SAP 3D Vi... |
| CVE-2022-22537 | MEDIUM | 6.5 | 0.9% | Feb 9, 2022 | When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visu... |
| CVE-2022-22535 | MEDIUM | 6.5 | 0.8% | Feb 9, 2022 | SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads t... |
| CVE-2022-22534 | MEDIUM | 6.1 | 0.8% | Feb 9, 2022 | Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may exp... |
| CVE-2022-21226 | MEDIUM | 5.5 | 0.3% | Feb 9, 2022 | Out-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to... |
| CVE-2022-21218 | MEDIUM | 5.5 | 0.3% | Feb 9, 2022 | Uncaught exception in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to... |
| CVE-2022-21157 | MEDIUM | 5.5 | 0.3% | Feb 9, 2022 | Improper access control in the Intel(R) Smart Campus Android application before version 6.1 may allow authenticated user... |
| CVE-2022-21156 | MEDIUM | 5.5 | 0.2% | Feb 9, 2022 | Access of uninitialized pointer in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenti... |
| CVE-2022-21153 | MEDIUM | 5.5 | 0.3% | Feb 9, 2022 | Improper access control in the Intel(R) Capital Global Summit Android application may allow an authenticated user to pot... |
| CVE-2022-21133 | MEDIUM | 5.5 | 0.2% | Feb 9, 2022 | Out-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to... |
| CVE-2022-20046 | MEDIUM | 5.5 | 0.1% | Feb 9, 2022 | In Bluetooth, there is a possible memory corruption due to a logic error. This could lead to local denial of service wit... |
| CVE-2022-20042 | MEDIUM | 5.5 | 0.1% | Feb 9, 2022 | In Bluetooth, there is a possible information disclosure due to incorrect error handling. This could lead to local infor... |
| CVE-2022-20039 | MEDIUM | 6.7 | 0.1% | Feb 9, 2022 | In ccu driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of ... |
| CVE-2022-20038 | MEDIUM | 6.7 | 0.1% | Feb 9, 2022 | In ccu driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalati... |
| CVE-2022-20037 | MEDIUM | 5.5 | 0.1% | Feb 9, 2022 | In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local inf... |
| CVE-2022-20036 | MEDIUM | 5.5 | 0.1% | Feb 9, 2022 | In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local inf... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now