2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2569MEDIUM5.5The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session d...
CVE-2022-2234HIGH8.8An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating sy...
CVE-2022-20122CRITICAL9.8The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be fre...
CVE-2022-37153MEDIUM6.1An issue was discovered in Artica Proxy 4.30.000000. There is a XSS vulnerability via the password parameter in /fw.logi...
CVE-2022-36633HIGH8.8Teleport 9.3.6 is vulnerable to Command injection leading to Remote Code Execution. An attacker can craft a malicious ss...
CVE-2022-33172MEDIUM5.5de.fac2 1.34 allows bypassing the User Presence protection mechanism when there is malware on the victim's PC.
CVE-2022-27812HIGH7.5Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific for...
CVE-2022-38089MEDIUM5.4Stored cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-ad...
CVE-2022-38080MEDIUM5.4Reflected cross-site scripting vulnerability in Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel...
CVE-2022-38078CRITICAL9.8Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially craft...
CVE-2022-37333HIGH8.8SQL injection vulnerability in the Exment ((PHP8) exceedone/exment v5.0.2 and earlier and exceedone/laravel-admin v3.0.0...
CVE-2022-37418MEDIUM6.4The Remote Keyless Entry (RKE) receiving unit on certain Nissan, Kia, and Hyundai vehicles through 2017 allows remote at...
CVE-2022-37305MEDIUM6.4The Remote Keyless Entry (RKE) receiving unit on certain Honda vehicles through 2018 allows remote attackers to perform ...
CVE-2022-36945MEDIUM6.4The Remote Keyless Entry (RKE) receiving unit on certain Mazda vehicles through 2020 allows remote attackers to perform ...
CVE-2022-25903HIGH7.5The package opcua from 0.0.0 are vulnerable to Denial of Service (DoS) via the ExtensionObjects and Variants objects, wh...
CVE-2022-24375HIGH7.5The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excess...
CVE-2022-38132HIGH8.8Command injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and ...
CVE-2022-31676HIGH7.8VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with loc...
CVE-2022-2938HIGH7.8A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by de...
CVE-2022-38463MEDIUM6.1ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.
CVE-2022-38172MEDIUM6.1ServiceNow through San Diego Patch 3 allows XSS via the name field during creation of a new dashboard for the Performanc...
CVE-2022-35115CRITICAL9.8IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the sear...
CVE-2022-1513HIGH8.8A potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution wh...
CVE-2022-38665MEDIUM6.5Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration fi...
CVE-2022-38664MEDIUM5.4Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Confi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now