2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-26138CRITICAL9.8The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in th...
CVE-2022-26137HIGH8.8A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to cause additional Servlet Fil...
CVE-2022-26136CRITICAL9.8A vulnerability in multiple Atlassian products allows a remote, unauthenticated attacker to bypass Servlet Filters used ...
CVE-2022-22424MEDIUM5.5IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to ...
CVE-2022-34049MEDIUM5.3An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files a...
CVE-2022-34048MEDIUM6.1Wavlink WN533A8 M33A8.V5030.190716 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via th...
CVE-2022-34047HIGH7.5An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows attackers to obtain usernames and passwords via v...
CVE-2022-34046HIGH7.5An access control issue in Wavlink WN533A8 M33A8.V5030.190716 allows attackers to obtain usernames and passwords via vie...
CVE-2022-34045CRITICAL9.8Wavlink WN530HG4 M30HG4.V5030.191116 was discovered to contain a hardcoded encryption/decryption key for its configurati...
CVE-2022-34042HIGH7.2Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /...
CVE-2022-33320HIGH7.8Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi E...
CVE-2022-33319CRITICAL9.1Out-of-bounds Read vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics...
CVE-2022-33318CRITICAL9.8Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi E...
CVE-2022-33317HIGH7.8Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 t...
CVE-2022-33316HIGH7.8Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi E...
CVE-2022-33315HIGH7.8Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi E...
CVE-2022-29834HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitsubishi Electric GENE...
CVE-2022-34150MEDIUM5.4The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object reference vulnerability on end...
CVE-2022-33944MEDIUM6.5The main MiCODUS MV720 GPS tracker web server has an authenticated insecure direct object references vulnerability on en...
CVE-2022-2199MEDIUM6.1The main MiCODUS MV720 GPS tracker web server has a reflected cross-site scripting vulnerability that could allow an att...
CVE-2022-2179MEDIUM6.5The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in th...
CVE-2022-2141CRITICAL9.8SMS-based GPS commands can be executed by MiCODUS MV720 GPS tracker without authentication.
CVE-2022-2107CRITICAL9.8The MiCODUS MV720 GPS tracker API server has an authentication mechanism that allows devices to use a hard-coded master ...
CVE-2022-1766HIGH7.5Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. ...
CVE-2022-1264HIGH8.8The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now