2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22223HIGH7.5On QFX10000 Series devices using Juniper Networks Junos OS when configured as transit IP/MPLS penultimate hop popping (P...
CVE-2022-22220MEDIUM5.9A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks J...
CVE-2022-22219MEDIUM5.9Due to the Improper Handling of an Unexpected Data Type in the processing of EVPN routes on Juniper Networks Junos OS an...
CVE-2022-22218HIGH7.5On SRX Series devices, an Improper Check for Unusual or Exceptional Conditions when using Certificate Management Protoco...
CVE-2022-22211HIGH7.5A limitless resource allocation vulnerability in FPC resources of Juniper Networks Junos OS Evolved on PTX Series allows...
CVE-2022-22208MEDIUM5.9A Use After Free vulnerability in the Routing Protocol Daemon (rdp) of Juniper Networks Junos OS and Junos OS Evolved al...
CVE-2022-22201HIGH7.5An Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Packet Forwarding Engine (P...
CVE-2022-22192HIGH7.5An Improper Validation of Syntactic Correctness of Input vulnerability in the kernel of Juniper Networks Junos OS Evolve...
CVE-2022-3569HIGH7.8Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalat...
CVE-2022-3158HIGH8.8Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation ...
CVE-2022-42147MEDIUM6.1kkFileView 4.0 is vulnerable to Cross Site Scripting (XSS) via controller\ Filecontroller.java.
CVE-2022-42143HIGH7.2Open Source SACCO Management System v1.0 is vulnerable to SQL Injection via /sacco_shield/manage_payment.php.
CVE-2022-42142HIGH7.2Online Tours & Travels Management System v1.0 is vulnerable to Arbitrary code execution via ip/tour/admin/operations/upd...
CVE-2022-41431MEDIUM5.4xzs v3.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /admin/question/edit. T...
CVE-2022-40606MEDIUM6.1MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a differ...
CVE-2022-3552HIGH7.2Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.
CVE-2022-3368HIGH8.8A vulnerability within the Software Updater functionality of Avira Security for Windows allowed an attacker with write a...
CVE-2022-38743HIGH8.8Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access c...
CVE-2022-42149CRITICAL9.8kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.
CVE-2022-41139MEDIUM5.4MITRE CALDERA 4.1.0 allows stored XSS via app.contact.gist (aka the gist contact configuration field), leading to execut...
CVE-2022-40605MEDIUM6.1MITRE CALDERA before 4.1.0 allows XSS in the Operations tab and/or Debrief plugin via a crafted operation name, a differ...
CVE-2022-3517HIGH7.5A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when...
CVE-2022-3421HIGH7.3An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned ...
CVE-2022-3382HIGH7.5HIWIN Robot System Software version 3.3.21.9869 does not properly address the terminated command source. As a result, an...
CVE-2022-3567MEDIUM6.4A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function in...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now