2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-40678HIGH7.8An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8...
CVE-2022-40677HIGH8.8A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0...
CVE-2022-40675HIGH7.4Some cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.1.0 through 9.1.8, 8...
CVE-2022-39948HIGH7.4An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all ...
CVE-2022-33871HIGH7.2A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and earlier, 6.4 all versions, version 6...
CVE-2022-33869HIGH8.8An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface ...
CVE-2022-30306HIGH8.8A stack-based buffer overflow vulnerability [CWE-121] in the CA sign functionality of FortiWeb version 7.0.1 and below, ...
CVE-2022-30303HIGH8.8An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0...
CVE-2022-27489HIGH7.2A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7...
CVE-2022-27482HIGH7.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC versio...
CVE-2022-26115HIGH7.5A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may a...
CVE-2022-27897HIGH7.5Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would load portions of maliciously...
CVE-2022-27892HIGH7.5Palantir Gotham versions prior to 3.22.11.2 included an unauthenticated endpoint that would have allowed an attacker to ...
CVE-2022-27890HIGH7.4It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net....
CVE-2022-40016HIGH7.5Use After Free (UAF) vulnerability in ireader media-server before commit 3e0f63f1d3553f75c7d4eb32fa7c7a1976a9ff84 in lib...
CVE-2022-38935HIGH8.8An issue was discovered in NiterForum version 2.5.0-beta in /src/main/java/cn/niter/forum/api/SsoApi.java and /src/main/...
CVE-2022-38868HIGH7.2SQL Injection vulnerability in Ehoney version 2.0.0 in models/protocol.go and models/images.go, allows attackers to exec...
CVE-2022-38867HIGH8.8SQL Injection vulnerability in rttys versions 4.0.0, 4.0.1, 4.0.2, and 4.4.x in api.go, allows attackers to execute arbi...
CVE-2022-45546HIGH7.5Information Disclosure in Authentication Component of ScreenCheck BadgeMaker 2.6.2.0 application allows internal attacke...
CVE-2022-42455HIGH7.8ASUS EC Tool driver (aka d.sys) 1beb15c90dcf7a5234ed077833a0a3e900969b60be1d04fcebce0a9f8994bdbb, as signed by ASUS and ...
CVE-2022-47508HIGH7.5Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but s...
CVE-2022-47507HIGH7.2SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa...
CVE-2022-47506HIGH7.8SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversar...
CVE-2022-47504HIGH7.2SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa...
CVE-2022-47503HIGH7.2SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now