2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36020MEDIUM6.1The typo3/html-sanitizer package is an HTML sanitizer, written in PHP, aiming to provide XSS-safe markup based on explic...
CVE-2022-3170HIGH7.8An out-of-bounds access issue was found in the Linux kernel sound subsystem. It could occur when the 'id->name' provided...
CVE-2022-3029HIGH7.5In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and...
CVE-2022-39801HIGH7.5SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even...
CVE-2022-39799MEDIUM6.1An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpa...
CVE-2022-39014MEDIUM5.3Under certain conditions SAP BusinessObjects Business Intelligence Platform Central Management Console (CMC) - version 4...
CVE-2022-35298MEDIUM6.1SAP NetWeaver Enterprise Portal (KMC) - version 7.50, does not sufficiently encode user-controlled inputs, resulting in ...
CVE-2022-35295MEDIUM4.9In SAP Host Agent (SAPOSCOL) - version 7.22, an attacker may use files created by saposcol to escalate privileges for th...
CVE-2022-35294MEDIUM5.4An attacker with basic business user privileges could craft and upload a malicious file to SAP NetWeaver Application Ser...
CVE-2022-35292HIGH7.8In SAP Business One application when a service is created, the executable path contains spaces and isn’t enclosed within...
CVE-2022-3190MEDIUM5.5Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denia...
CVE-2022-3027MEDIUM5.7The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could...
CVE-2022-38542CRITICAL9.8Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the kill...
CVE-2022-38541CRITICAL9.8Archery v1.8.3 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_time and stop_ti...
CVE-2022-38540CRITICAL9.8Archery v1.4.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the ThreadIDs parameter in the crea...
CVE-2022-38539CRITICAL9.8Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/app...
CVE-2022-38538CRITICAL9.8Archery v1.7.0 to v1.8.5 was discovered to contain a SQL injection vulnerability via the checksum parameter in the repor...
CVE-2022-38537CRITICAL9.8Archery v1.4.5 to v1.8.5 was discovered to contain multiple SQL injection vulnerabilities via the start_file, end_file, ...
CVE-2022-38453MEDIUM4.4Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation se...
CVE-2022-38100HIGH7.5The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with net...
CVE-2022-38069MEDIUM6.1Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with mom...
CVE-2022-36782HIGH8.6Pal Electronics Systems - Pal Gate Authorization Errors. The vulnerability is an authorization problem in PalGate device...
CVE-2022-36780MEDIUM5.3Avdor CIS - crystal quality Credentials Management Errors. The product is phone call recorder, you can hear all the reco...
CVE-2022-36779CRITICAL9.8PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Pro...
CVE-2022-36778MEDIUM5.4insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now