2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-31324MEDIUM6.5An arbitrary file download vulnerability in the downloadAction() function of Penta Security Systems Inc WAPPLES v6.0 r3 ...
CVE-2022-31322HIGH7.8Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges via overwriting files us...
CVE-2022-40623HIGH8.8The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 does not utilize anti-CSRF tokens, which, ...
CVE-2022-40622HIGH8.8The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and doe...
CVE-2022-40621HIGH7.5Because the WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 and earlier communicates over HTTP...
CVE-2022-39821HIGH7.5In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The we...
CVE-2022-39819HIGH8.8In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execut...
CVE-2022-39817HIGH8.8In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker....
CVE-2022-39816MEDIUM6.5In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit confi...
CVE-2022-39815CRITICAL9.8In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated ...
CVE-2022-39814MEDIUM6.1In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.
CVE-2022-38637CRITICAL9.8Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Pa...
CVE-2022-38497MEDIUM5.5LIEF commit 365a16a was discovered to contain a segmentation violation via the component CoreFile.tcc:69.
CVE-2022-38496MEDIUM5.5LIEF commit 365a16a was discovered to contain a reachable assertion abort via the component BinaryStream.hpp.
CVE-2022-38495HIGH7.8LIEF commit 365a16a was discovered to contain a heap-buffer overflow via the function print_binary at /c/macho_reader.c.
CVE-2022-38329MEDIUM4.3A CSRF vulnerability in Shopxian CMS 3.0.0 could allow an unauthenticated, remote attacker to craft a malicious link, po...
CVE-2022-38307MEDIUM5.5LIEF commit 5d1d643 was discovered to contain a segmentation violation via the function LIEF::MachO::SegmentCommand::fil...
CVE-2022-38306HIGH7.8LIEF commit 5d1d643 was discovered to contain a heap-buffer overflow in the component /core/CorePrPsInfo.tcc.
CVE-2022-36768HIGH7.8IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the invscout c...
CVE-2022-35637MEDIUM6.5IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service after entering ...
CVE-2022-34356HIGH7.8IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel...
CVE-2022-34336MEDIUM5.4IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows...
CVE-2022-22483MEDIUM6.5IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some s...
CVE-2022-22330MEDIUM5.3IBM Control Desk 7.6.1 could allow a remote attacker to obtain sensitive information, caused by the failure to set the H...
CVE-2022-22329MEDIUM4.3IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be ab...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now