2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45858 | HIGH | 7.4 | 0.2% | May 3, 2023 | A use of a weak cryptographic algorithm vulnerability [CWE-327] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.0 all ... |
| CVE-2022-3405 | HIGH | 8.8 | 5.3% | May 3, 2023 | Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following... |
| CVE-2022-30995 | HIGH | 7.5 | 3.3% | May 3, 2023 | Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Prot... |
| CVE-2022-30759 | HIGH | 8.8 | 1.1% | May 2, 2023 | In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to es... |
| CVE-2022-47878 | HIGH | 8.8 | 38.1% | May 2, 2023 | Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authentica... |
| CVE-2022-47876 | HIGH | 8.8 | 7.0% | May 2, 2023 | The integrator in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to create Jobs to execute arbitrary code v... |
| CVE-2022-47875 | HIGH | 8.8 | 10.2% | May 2, 2023 | A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to ex... |
| CVE-2022-40504 | HIGH | 7.5 | 0.4% | May 2, 2023 | Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. |
| CVE-2022-40508 | HIGH | 7.5 | 0.4% | May 2, 2023 | Transient DOS due to reachable assertion in Modem while processing config related to cross carrier scheduling, which is ... |
| CVE-2022-40505 | HIGH | 7.5 | 0.4% | May 2, 2023 | Information disclosure due to buffer over-read in Modem while parsing DNS hostname. |
| CVE-2022-34144 | HIGH | 7.5 | 0.4% | May 2, 2023 | Transient DOS due to reachable assertion in Modem during OSI decode scheduling. |
| CVE-2022-33305 | HIGH | 7.5 | 0.4% | May 2, 2023 | Transient DOS due to NULL pointer dereference in Modem while sending invalid messages in DCCH. |
| CVE-2022-33304 | HIGH | 7.5 | 0.4% | May 2, 2023 | Transient DOS due to NULL pointer dereference in Modem while performing pullup for received TCP/UDP packet. |
| CVE-2022-33292 | HIGH | 7.8 | 0.1% | May 2, 2023 | Memory corruption in Qualcomm IPC due to use after free while receiving the incoming packet and reposting it. |
| CVE-2022-33281 | HIGH | 7.8 | 0.1% | May 2, 2023 | Memory corruption due to improper validation of array index in computer vision while testing EVA kernel without sending ... |
| CVE-2022-25713 | HIGH | 7.8 | 0.1% | May 2, 2023 | Memory corruption in Automotive due to Improper Restriction of Operations within the Bounds of a Memory Buffer while exp... |
| CVE-2022-48483 | HIGH | 7.5 | 1.7% | May 2, 2023 | 3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 fil... |
| CVE-2022-48482 | HIGH | 7.5 | 1.8% | May 2, 2023 | 3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certa... |
| CVE-2022-4568 | HIGH | 7 | 0.2% | May 1, 2023 | A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges. |
| CVE-2022-41736 | HIGH | 7.8 | 0.2% | Apr 29, 2023 | IBM Spectrum Scale Container Native Storage Access 5.1.2.1 through 5.1.6.0 contains an unspecified vulnerability that... |
| CVE-2022-41399 | HIGH | 7.5 | 0.6% | Apr 28, 2023 | The optional Web Screens feature for Sage 300 through version 2022 uses a hard-coded 40-byte blowfish key ("PASS_KEY") t... |
| CVE-2022-41398 | HIGH | 7.5 | 0.5% | Apr 28, 2023 | The optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accomp... |
| CVE-2022-38583 | HIGH | 7.8 | 0.3% | Apr 28, 2023 | On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Serve... |
| CVE-2022-48481 | HIGH | 7.8 | 0.2% | Apr 28, 2023 | In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible |
| CVE-2022-37326 | HIGH | 7.8 | 0.3% | Apr 27, 2023 | Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 wind... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now