2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-33891HIGH8.8The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authen...
CVE-2022-27434CRITICAL9.8UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileN...
CVE-2022-33903HIGH7.5Tor 0.4.7.x before 0.4.7.8 allows a denial of service via the wedging of RTT estimation.
CVE-2022-32985CRITICAL9.8libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor Account for SSH logins on ...
CVE-2022-31213HIGH7.5An issue was discovered in dbus-broker before 31. Multiple NULL pointer dereferences can be found when supplying a malfo...
CVE-2022-31212HIGH7.5An issue was discovered in dbus-broker before 31. It depends on c-uitl/c-shquote to parse the DBus service's Exec line. ...
CVE-2022-31211CRITICAL9.8An issue was discovered in Infiray IRAY-A8Z3 1.0.957. There is a blank root password for TELNET by default.
CVE-2022-31210CRITICAL9.8An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The binary file /usr/local/sbin/webproject/set_param.cgi contains ...
CVE-2022-31209CRITICAL9.8An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The firmware contains a potential buffer overflow by calling strcp...
CVE-2022-31208HIGH8.8An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The webserver contains an endpoint that can execute arbitrary comm...
CVE-2022-31202MEDIUM6.5The export function in SoftGuard Web (SGW) before 5.1.5 allows directory traversal to read an arbitrary local file via e...
CVE-2022-31201MEDIUM5.4SoftGuard Web (SGW) before 5.1.5 allows HTML injection.
CVE-2022-30982MEDIUM5.4An issue was discovered in Gentics CMS before 5.43.1. There is stored XSS in the profile description and in the username...
CVE-2022-30981HIGH8.8An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an attacker is able to deserial...
CVE-2022-28809HIGH7.8An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists w...
CVE-2022-28808HIGH7.8An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists w...
CVE-2022-28807HIGH7.8An issue was discovered in Open Design Alliance Drawings SDK before 2023.2. An Out-of-Bounds Read vulnerability exists w...
CVE-2022-26482HIGH7.2An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an a...
CVE-2022-26481HIGH8.8An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificat...
CVE-2022-26479CRITICAL9.8An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created v...
CVE-2022-32263HIGH7.5Pexip Infinity before 28.1 allows remote attackers to trigger a software abort via G.719.
CVE-2022-29286HIGH7.5Pexip Infinity 27 before 28.0 allows remote attackers to trigger excessive resource consumption and termination because ...
CVE-2022-26352CRITICAL9.8An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form req...
CVE-2022-30622HIGH7.3Disclosure of information - the system allows you to view usernames and passwords without permissions, thus it will be p...
CVE-2022-27937HIGH7.5Pexip Infinity before 27.3 allows remote attackers to trigger excessive resource consumption via H.264.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now