2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-23049MEDIUM5.4Exponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header wh...
CVE-2022-23047MEDIUM4.8Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organi...
CVE-2022-22812MEDIUM6.1A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that...
CVE-2022-22809MEDIUM5.3A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch...
CVE-2022-22780MEDIUM6.5The Zoom Client for Meetings chat functionality was susceptible to Zip bombing attacks in the following product versions...
CVE-2022-22546MEDIUM5.4Due to improper HTML encoding in input control summary, an authorized attacker can execute XSS vulnerability in SAP Busi...
CVE-2022-22545MEDIUM4.9A high privileged user who has access to transaction SM59 can read connection details stored with the destination for ht...
CVE-2022-22542MEDIUM6.5S/4HANA Supplier Factsheet exposes the private address and bank details of an Employee Business Partner with Supplier Ro...
CVE-2022-22539MEDIUM6.5When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterpr...
CVE-2022-22538MEDIUM6.5When a user opens a manipulated Adobe Illustrator file format (.ai, ai.x3d) received from untrusted sources in SAP 3D Vi...
CVE-2022-22537MEDIUM6.5When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted sources in SAP 3D Visu...
CVE-2022-22535MEDIUM6.5SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads t...
CVE-2022-22534MEDIUM6.1Due to insufficient encoding of user input, SAP NetWeaver allows an unauthenticated attacker to inject code that may exp...
CVE-2022-21226MEDIUM5.5Out-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to...
CVE-2022-21218MEDIUM5.5Uncaught exception in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to...
CVE-2022-21157MEDIUM5.5Improper access control in the Intel(R) Smart Campus Android application before version 6.1 may allow authenticated user...
CVE-2022-21156MEDIUM5.5Access of uninitialized pointer in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenti...
CVE-2022-21153MEDIUM5.5Improper access control in the Intel(R) Capital Global Summit Android application may allow an authenticated user to pot...
CVE-2022-21133MEDIUM5.5Out-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to...
CVE-2022-20046MEDIUM5.5In Bluetooth, there is a possible memory corruption due to a logic error. This could lead to local denial of service wit...
CVE-2022-20042MEDIUM5.5In Bluetooth, there is a possible information disclosure due to incorrect error handling. This could lead to local infor...
CVE-2022-20039MEDIUM6.7In ccu driver, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of ...
CVE-2022-20038MEDIUM6.7In ccu driver, there is a possible memory corruption due to an incorrect bounds check. This could lead to local escalati...
CVE-2022-20037MEDIUM5.5In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local inf...
CVE-2022-20036MEDIUM5.5In ion driver, there is a possible information disclosure due to an incorrect bounds check. This could lead to local inf...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now