2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36020 | MEDIUM | 6.1 | 0.6% | Sep 13, 2022 | The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explic... |
| CVE-2022-3170 | HIGH | 7.8 | 0.2% | Sep 13, 2022 | An out-of-bounds access issue was found in the Linux kernel sound subsystem. It could occur when the 'id->name' provided... |
| CVE-2022-3029 | HIGH | 7.5 | 0.7% | Sep 13, 2022 | In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and... |
| CVE-2022-39801 | HIGH | 7.5 | 0.6% | Sep 13, 2022 | SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even... |
| CVE-2022-39799 | MEDIUM | 6.1 | 0.4% | Sep 13, 2022 | An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpa... |
| CVE-2022-39014 | MEDIUM | 5.3 | 0.4% | Sep 13, 2022 | Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 4... |
| CVE-2022-35298 | MEDIUM | 6.1 | 0.4% | Sep 13, 2022 | SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in ... |
| CVE-2022-35295 | MEDIUM | 4.9 | 1.2% | Sep 13, 2022 | In SAP Host Agent (SAPOSCOL) - version 7.22, an attacker may use files created by saposcol to escalate privileges for th... |
| CVE-2022-35294 | MEDIUM | 5.4 | 0.4% | Sep 13, 2022 | An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Ser... |
| CVE-2022-35292 | HIGH | 7.8 | 0.2% | Sep 13, 2022 | In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within... |
| CVE-2022-3190 | MEDIUM | 5.5 | 1.7% | Sep 13, 2022 | Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denia... |
| CVE-2022-3027 | MEDIUM | 5.7 | 0.3% | Sep 13, 2022 | The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could... |
| CVE-2022-38542 | CRITICAL | 9.8 | 0.9% | Sep 13, 2022 | Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill... |
| CVE-2022-38541 | CRITICAL | 9.8 | 0.9% | Sep 13, 2022 | Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_ti... |
| CVE-2022-38540 | CRITICAL | 9.8 | 0.9% | Sep 13, 2022 | Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the crea... |
| CVE-2022-38539 | CRITICAL | 9.8 | 0.9% | Sep 13, 2022 | Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/app... |
| CVE-2022-38538 | CRITICAL | 9.8 | 0.9% | Sep 13, 2022 | Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the repor... |
| CVE-2022-38537 | CRITICAL | 9.8 | 0.8% | Sep 13, 2022 | Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, ... |
| CVE-2022-38453 | MEDIUM | 4.4 | 0.2% | Sep 13, 2022 | Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation se... |
| CVE-2022-38100 | HIGH | 7.5 | 0.8% | Sep 13, 2022 | The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with net... |
| CVE-2022-38069 | MEDIUM | 6.1 | 0.3% | Sep 13, 2022 | Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with mom... |
| CVE-2022-36782 | HIGH | 8.6 | 0.4% | Sep 13, 2022 | Pal Electronics Systems - Pal Gate Authorization Errors. The vulnerability is an authorization problem in PalGate device... |
| CVE-2022-36780 | MEDIUM | 5.3 | 0.4% | Sep 13, 2022 | Avdor CIS - crystal quality Credentials Management Errors. The product is phone call recorder, you can hear all the reco... |
| CVE-2022-36779 | CRITICAL | 9.8 | 2.3% | Sep 13, 2022 | PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Pro... |
| CVE-2022-36778 | MEDIUM | 5.4 | 0.4% | Sep 13, 2022 | insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now