2022 CVE Vulnerabilities

27,528 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-20772MEDIUM5.3A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenti...
CVE-2022-27893MEDIUM4.2The Foundry Magritte plugin osisoft-pi-web-connector versions 0.15.0 - 0.43.0 was found to be logging in a manner that c...
CVE-2022-41671HIGH7.8A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that al...
CVE-2022-41670HIGH7.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGI...
CVE-2022-41669HIGH7.8A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows...
CVE-2022-3721MEDIUM4.6Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.
CVE-2022-41668HIGH7.8A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load ...
CVE-2022-41667HIGH7.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allow...
CVE-2022-3340HIGH7.2XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administra...
CVE-2022-3023CRITICAL9.8Use of Externally-Controlled Format String in GitHub repository pingcap/tidb prior to 6.4.0, 6.1.3.
CVE-2022-38582MEDIUM6.5Incorrect access control in the anti-virus driver wsdkd.sys of Watchdog Antivirus v1.4.158 allows attackers to write arb...
CVE-2022-33684HIGH8.1The Apache Pulsar C++ Client does not verify peer TLS certificates when making HTTPS calls for the OAuth2.0 Client Crede...
CVE-2022-44724MEDIUM5.4The Handy Tip macro in Stiltsoft Handy Macros for Confluence Server/Data Center 3.x before 3.5.5 allows remote attackers...
CVE-2022-41666HIGH7.8A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user...
CVE-2022-43571HIGH8.8In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through t...
CVE-2022-43561MEDIUM4.8In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user that holds the “power” Splunk role can store...
CVE-2022-38168CRITICAL9.1Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote un...
CVE-2022-44628MEDIUM4.8Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in JumpDEMAND Inc. 4ECPS Web Forms plugin <= 0.2.17 on Wo...
CVE-2022-44627MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in David Cole Simple SEO plugin <= 1.8.12 on WordPress allows attackers ...
CVE-2022-43574HIGH7.5"IBM Robotic Process Automation 21.0.1, 21.0.2, 21.0.3, 21.0.4, and 21.0.5 is vulnerable to incorrect permission assignm...
CVE-2022-43495HIGH7.5OpenHarmony-v3.1.2 and prior versions had a DOS vulnerability in distributedhardware_device_manager when joining a netwo...
CVE-2022-43451MEDIUM6.5OpenHarmony-v3.1.2 and prior versions had an Multiple path traversal vulnerability in appspawn and nwebspawn services. L...
CVE-2022-43449MEDIUM5.5OpenHarmony-v3.1.2 and prior versions had an Arbitrary file read vulnerability via download_server. Local attackers can ...
CVE-2022-43063HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-43062HIGH7.2Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now