2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3732CRITICAL9.8A vulnerability was found in seccome Ehoney and classified as critical. Affected by this issue is some unknown functiona...
CVE-2022-3731CRITICAL9.8A vulnerability has been found in seccome Ehoney and classified as critical. Affected by this vulnerability is an unknow...
CVE-2022-3730CRITICAL9.8A vulnerability, which was classified as critical, was found in seccome Ehoney. Affected is an unknown function of the f...
CVE-2022-3729CRITICAL9.8A vulnerability, which was classified as critical, has been found in seccome Ehoney. This issue affects some unknown pro...
CVE-2022-26884MEDIUM6.5Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.
CVE-2022-3616HIGH7.5Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequen...
CVE-2022-37915CRITICAL9.8A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauth...
CVE-2022-37914CRITICAL9.8Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauth...
CVE-2022-37913CRITICAL9.8Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauth...
CVE-2022-33859CRITICAL9.8A security vulnerability was discovered in the Eaton Foreseer EPMS software. Foreseer EPMS connects an operation’s vast ...
CVE-2022-31678CRITICAL9.1VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V dep...
CVE-2022-3379HIGH7.8 Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a ...
CVE-2022-3378HIGH7.8 Horner Automation's Cscape version 9.90 SP 7 and prior does not properly validate user-supplied data. If a user opens a...
CVE-2022-41773HIGH8.8The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckDIA...
CVE-2022-41702MEDIUM5.4The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi...
CVE-2022-41701MEDIUM5.4The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi...
CVE-2022-41651MEDIUM5.4The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi...
CVE-2022-41627HIGH7.6 The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encr...
CVE-2022-41555MEDIUM5.4The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi...
CVE-2022-41133HIGH8.8The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in GetDIAE_...
CVE-2022-40967HIGH8.8The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a SQL injection that exists in CheckIoT...
CVE-2022-40965MEDIUM5.4The affected product DIAEnergie (versions prior to v1.9.01.002) is vulnerable to a stored cross-site scripting vulnerabi...
CVE-2022-40876CRITICAL9.8In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can ...
CVE-2022-3387MEDIUM5.3 Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could r...
CVE-2022-3386CRITICAL9.8 Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now