2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-35228HIGH8.8SAP BusinessObjects CMC allows an unauthenticated attacker to retrieve token information over the network which would ot...
CVE-2022-35227MEDIUM6.1A vulnerability in SAP NW EP (WPC) - versions 7.30, 7.31, 7.40, 7.50, which does not sufficiently validate user-controll...
CVE-2022-35225MEDIUM6.1SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-c...
CVE-2022-35224MEDIUM6.1SAP Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-controlled ...
CVE-2022-35172MEDIUM6.1SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user-c...
CVE-2022-35171MEDIUM5.5When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterpri...
CVE-2022-35170MEDIUM6.1SAP NetWeaver Enterprise Portal does - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, not sufficiently encode user-c...
CVE-2022-35169MEDIUM6SAP BusinessObjects Business Intelligence Platform (LCM) - versions 420, 430, allows an attacker with an admin privilege...
CVE-2022-35168HIGH7.5Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-...
CVE-2022-32249HIGH7.5Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit...
CVE-2022-32248MEDIUM5.3Due to missing input validation in the Manage Checkbooks component of SAP S/4HANA - version 101, 102, 103, 104, 105, 106...
CVE-2022-32247MEDIUM6.1SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution ...
CVE-2022-32246MEDIUM4.6SAP Busines Objects Business Intelligence Platform (Visual Difference Application) - versions 420, 430, allows an authen...
CVE-2022-31655MEDIUM5.4VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improp...
CVE-2022-31654MEDIUM5.4VMware vRealize Log Insight in versions prior to 8.8.2 contain a stored cross-site scripting vulnerability due to improp...
CVE-2022-31598MEDIUM5.4Due to insufficient input validation, SAP Business Objects - version 420, allows an authenticated attacker to submit a m...
CVE-2022-31597MEDIUM5.4Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extens...
CVE-2022-31593HIGH8.8SAP Business One client - version 10.0 allows an attacker with low privileges, to inject code that can be executed by th...
CVE-2022-31592MEDIUM4.3The application SAP Enterprise Extension Defense Forces & Public Security - versions 605, 606, 616,617,618, 802, 803, 80...
CVE-2022-31591HIGH7.8SAP BusinessObjects BW Publisher Service - versions 420, 430, uses a search path that contains an unquoted element. A lo...
CVE-2022-31134MEDIUM4.9Zulip is an open-source team collaboration tool. Zulip Server versions 2.1.0 above have a user interface tool, accessibl...
CVE-2022-31012HIGH7.3Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 ...
CVE-2022-2211MEDIUM6.5A vulnerability was found in libguestfs. This issue occurs while calculating the greatest possible number of matching ke...
CVE-2022-29619MEDIUM6.5Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.x - versions 420,430 allows user Administr...
CVE-2022-29187HIGH7.8Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now