2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34160MEDIUM5.4IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML co...
CVE-2022-35406MEDIUM4.3A URL disclosure issue was discovered in Burp Suite before 2022.6. If a user views a crafted response in the Repeater or...
CVE-2022-28624MEDIUM4.8A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vu...
CVE-2022-28623CRITICAL9.8Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorize...
CVE-2022-33011HIGH8.8Known v1.3.1+2020120201 was discovered to allow attackers to perform an account takeover via a host header injection att...
CVE-2022-32115MEDIUM6.1An issue in the isSVG() function of Known v1.2.2+2020061101 allows attackers to execute arbitrary code via a crafted SVG...
CVE-2022-31290MEDIUM5.4A cross-site scripting (XSS) vulnerability in Known v1.2.2+2020061101 allows authenticated attackers to execute arbitrar...
CVE-2022-30852MEDIUM4.3Known v1.3.1 was discovered to contain an Insecure Direct Object Reference (IDOR).
CVE-2022-1245CRITICAL9.8A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client a...
CVE-2022-32061MEDIUM4.8An arbitrary file upload vulnerability in the Select User function under the People Menu component of Snipe-IT v6.0.2 al...
CVE-2022-32060MEDIUM4.8An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to ...
CVE-2022-33936CRITICAL9.8Cloud Mobility for Dell EMC Storage, 1.3.0.XXX contains a RCE vulnerability. A non-privileged user could potentially exp...
CVE-2022-32481HIGH7.8Dell PowerProtect Cyber Recovery, versions prior to 19.11, contain a privilege escalation vulnerability on virtual appli...
CVE-2022-31029MEDIUM4.8AdminLTE is a Pi-hole Dashboard for stats and configuration. In affected versions inserting code like `<script>alert("XS...
CVE-2022-2191HIGH7.5In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffer...
CVE-2022-2048HIGH7.5In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug...
CVE-2022-2047LOW2.7In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the...
CVE-2022-33680HIGH8.3Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-34592CRITICAL9.8Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obt...
CVE-2022-33098MEDIUM6.1Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function....
CVE-2022-32449CRITICAL9.8TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in...
CVE-2022-32058HIGH7.5An infinite loop in the function httpRpmPass of TP-Link TL-WR741N/TL-WR742N V1/V2/V3_130415 allows attackers to cause a ...
CVE-2022-32056CRITICAL9.8Online Accreditation Management v1.0 was discovered to contain a SQL injection vulnerability via the USERNAME parameter ...
CVE-2022-32055HIGH7.5Inout Homestay v2.2 was discovered to contain a SQL injection vulnerability via the guests parameter at /index.php?page=...
CVE-2022-32054CRITICAL9.8Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now