2022 CVE Vulnerabilities

27,528 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-45061HIGH7.5An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing s...
CVE-2022-40797CRITICAL9.8Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf....
CVE-2022-45060HIGH7.5An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x bef...
CVE-2022-45059HIGH7.5An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be perf...
CVE-2022-3890CRITICAL9.6Heap buffer overflow in Crashpad in Google Chrome on Android prior to 107.0.5304.106 allowed a remote attacker who had c...
CVE-2022-3889HIGH8.8Type confusion in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corr...
CVE-2022-3888HIGH8.8Use after free in WebCodecs in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit he...
CVE-2022-3887HIGH8.8Use after free in Web Workers in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit ...
CVE-2022-3886HIGH8.8Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially e...
CVE-2022-3885HIGH8.8Use after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corr...
CVE-2022-39390Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-36534. Reason: This candidate is a reservation d...
CVE-2022-43144MEDIUM5.4A cross-site scripting (XSS) vulnerability in Canteen Management System v1.0 allows attackers to execute arbitrary web s...
CVE-2022-39328HIGH8.1Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 co...
CVE-2022-30515MEDIUM5.3ZKTeco BioTime 8.5.4 is missing authentication on folders containing employee photos, allowing an attacker to view them ...
CVE-2022-41260MEDIUM6.1SAP Financial Consolidation - version 1010, does not sufficiently encode user-controlled input which may allow an unauth...
CVE-2022-41259MEDIUM6.5SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywh...
CVE-2022-41258MEDIUM6.5Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker to in...
CVE-2022-41215MEDIUM4.7SAP NetWeaver ABAP Server and ABAP Platform allows an unauthenticated attacker to redirect users to a malicious site due...
CVE-2022-41214HIGH8.7Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with hi...
CVE-2022-41212MEDIUM4.9Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with hi...
CVE-2022-41211HIGH7.8Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D ...
CVE-2022-41208MEDIUM5.4Due to insufficient input validation, SAP Financial Consolidation - version 1010, allows an authenticated attacker with ...
CVE-2022-41207MEDIUM6.1SAP Biller Direct allows an unauthenticated attacker to craft a legitimate looking URL. When clicked by an unsuspecting ...
CVE-2022-41205MEDIUM6.1SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attack...
CVE-2022-41203HIGH8.8In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated atta...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now