2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-48363HIGH7.5In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Dra...
CVE-2022-48362HIGH8.8Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName ...
CVE-2022-44310HIGH7.5In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obt...
CVE-2022-1607HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plan...
CVE-2022-4492HIGH7.5The undertow client is not checking the server identity presented by the server certificate in https connections. This i...
CVE-2022-48341HIGH8.8ThingsBoard 3.4.1 could allow a remote authenticated attacker to achieve Vertical Privilege Escalation. A Tenant Adminis...
CVE-2022-45600HIGH8.8Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers...
CVE-2022-43873HIGH8.8An authenticated user can exploit a vulnerability in the IBM Spectrum Virtualize 8.2, 8.3, 8.4, and 8.5 GUI to execute c...
CVE-2022-2883HIGH7.5In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Serv...
CVE-2022-48282HIGH7.2Under very specific circumstances (see Required configuration section below), a privileged user is able to cause arbitra...
CVE-2022-3353HIGH7.5 A vulnerability exists in the IEC 61850 communication stack that affects multiple Hitachi Energy products.  An attac...
CVE-2022-31394HIGH7.5Hyperium Hyper before 0.14.19 does not allow for customization of the max_header_list_size method in the H2 third-party ...
CVE-2022-48340HIGH7.5In Gluster GlusterFS 11.0, there is an xlators/cluster/dht/src/dht-common.c dht_setxattr_mds_cbk use-after-free.
CVE-2022-48339HIGH7.8An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-iste...
CVE-2022-48338HIGH7.3An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local comm...
CVE-2022-44216HIGH7.5Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without kno...
CVE-2022-47909HIGH7.8Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <=...
CVE-2022-46836HIGH8.8PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Check...
CVE-2022-46303HIGH7.5Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allo...
CVE-2022-40231HIGH8.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 could allow an authenti...
CVE-2022-34351HIGH7.5IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain secu...
CVE-2022-43930HIGH7.5IBM Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 is vulnerable to an Information Disclosure as sensitive informa...
CVE-2022-41734HIGH7.5IBM Maximo Asset Management 7.6.1.2 and 7.6.1.3 could allow a remote attacker to obtain sensitive information when a det...
CVE-2022-40232HIGH8.8 IBM Sterling B2B Integrator Standard Edition 6.1.0.0 through 6.1.1.1, and 6.1.2.0 could allow an authenticated user to ...
CVE-2022-20803HIGH7.5A vulnerability in the OLE2 file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 could allow an unaut...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now