2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-41316MEDIUM5.3HashiCorp Vault and Vault Enterprise’s TLS certificate auth method did not initially load the optionally configured CRL ...
CVE-2022-39299HIGH8.1Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. A remote attacker ...
CVE-2022-41351MEDIUM6.1In Zimbra Collaboration Suite (ZCS) 8.8.15, at the URL /h/calendar, one can trigger XSS by adding JavaScript code to the...
CVE-2022-41350MEDIUM6.1In Zimbra Collaboration Suite (ZCS) 8.8.15, /h/search?action=voicemail&action=listen accepts a phone parameter that is v...
CVE-2022-41349MEDIUM6.1In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/compose accepts an attachUrl parameter that is vulnerable to R...
CVE-2022-41348MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via the onerror attribute of an IMG element, le...
CVE-2022-37601CRITICAL9.8Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable ...
CVE-2022-34391HIGH7.8Dell Client BIOS Versions prior to the remediated version contain an improper input validation vulnerability. A local au...
CVE-2022-34390HIGH7.8Dell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious user may potentially e...
CVE-2022-33937HIGH7.1Dell GeoDrive, Versions 1.0 - 2.2, contain a Path Traversal Vulnerability in the reporting function. A local, low privil...
CVE-2022-33922HIGH7.8Dell GeoDrive, versions prior to 2.2, contains Insecure File and Folder Permissions vulnerabilities. A low privilege att...
CVE-2022-33921HIGH7.8Dell GeoDrive, versions prior to 2.2, contains Multiple DLL Hijacking Vulnerabilities. A low privilege attacker could po...
CVE-2022-33920HIGH7.8Dell GeoDrive, versions prior to 2.2, contains an Unquoted File Path vulnerability. A low privilege attacker could poten...
CVE-2022-33919HIGH7.8Dell GeoDrive, versions 2.1 - 2.2, contains an information disclosure vulnerability in GUI. An authenticated non-admin u...
CVE-2022-33918MEDIUM5.5Dell GeoDrive, Versions 2.1 - 2.2, contains an information disclosure vulnerability. An authenticated non-admin user cou...
CVE-2022-32493HIGH7.8Dell BIOS contains an Stack-Based Buffer Overflow vulnerability. A local authenticated malicious user may potentially ex...
CVE-2022-32491HIGH7.8Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit ...
CVE-2022-32489HIGH7.8Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl...
CVE-2022-32488HIGH7.8Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl...
CVE-2022-32487HIGH7.8Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl...
CVE-2022-32485HIGH7.8Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl...
CVE-2022-32484MEDIUM4.4Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privilege...
CVE-2022-32483MEDIUM4.4Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privilege...
CVE-2022-31228CRITICAL9.8Dell EMC XtremIO versions prior to X2 6.4.0-22 contain a bruteforce vulnerability. A remote unauthenticated attacker can...
CVE-2022-42087MEDIUM6.5Tenda AX1803 US_AX1803v2.0br_v1.0.0.1_2994_CN_ZGYD01_4 is vulnerable to Cross Site Request Forgery (CSRF) via function f...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now