2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2406MEDIUM6.5The legacy Slack import feature in Mattermost version 6.7.0 and earlier fails to properly limit the sizes of imported fi...
CVE-2022-2401MEDIUM6.5Unrestricted information disclosure of all users in Mattermost version 6.7.0 and earlier allows team members to access s...
CVE-2022-22460HIGH7.5IBM Security Verify Identity Manager 10.0 contains sensitive information in the source code repository that could be use...
CVE-2022-22453HIGH7.5IBM Security Verify Identity Manager 10.0 uses weaker than expected cryptographic algorithms that could allow an attacke...
CVE-2022-22452HIGH7.5IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker ...
CVE-2022-22450LOW3.8IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extensio...
CVE-2022-35283MEDIUM6.5IBM Security Verify Information Queue 10.0.2 could allow an authenticated user to cause a denial of service with a speci...
CVE-2022-22477MEDIUM6.1IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to e...
CVE-2022-22473MEDIUM5.3IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information ca...
CVE-2022-32225MEDIUM6.1A reflected DOM-Based XSS vulnerability has been discovered in the Help directory of Veeam Management Pack for Microsoft...
CVE-2022-32223HIGH7.3Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnera...
CVE-2022-32222MEDIUM5.3A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default pa...
CVE-2022-32215MEDIUM6.5The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line T...
CVE-2022-32214MEDIUM6.5The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequenc...
CVE-2022-32213MEDIUM6.5The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate ...
CVE-2022-32212HIGH8.1A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAll...
CVE-2022-32210MEDIUM6.5`Undici.ProxyAgent` never verifies the remote server's certificate, and always exposes all request & response data to th...
CVE-2022-2393MEDIUM5.7A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-bas...
CVE-2022-29593MEDIUM5.9relay_cgi.cgi on Dingtian DT-R002 2CH relay devices with firmware 3.1.276A allows an attacker to replay HTTP post reques...
CVE-2022-28876HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant and in certain WithSecure products whereby the...
CVE-2022-1662MEDIUM5.5In convert2rhel, there's an ansible playbook named ansible/run-convert2rhel.yml which passes the Red Hat Subscription Ma...
CVE-2022-30024HIGH8.8A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated...
CVE-2022-30113CRITICAL9.8Electronic mall system 1.0_build20200203 is affected vulnerable to SQL Injection.
CVE-2022-28377HIGH7.5On Verizon 5G Home LVSKIHP InDoorUnit (IDU) 3.4.66.162 and OutDoorUnit (ODU) 3.33.101.0 devices, the CRTC and ODU RPC en...
CVE-2022-28375CRITICAL9.8Verizon 5G Home LVSKIHP OutDoorUnit (ODU) 3.33.101.0 does not property sanitize user-controlled parameters within the cr...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now