2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22390HIGH7.5IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an information disclosure cause...
CVE-2022-22389MEDIUM6.5IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to a denial of service as the server m...
CVE-2022-33953MEDIUM4.6IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensit...
CVE-2022-31767CRITICAL9.8IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by send...
CVE-2022-29330MEDIUM4.9Missing access control in the backup system of Telesoft VitalPBX before 3.2.1 allows attackers to access the PJSIP and S...
CVE-2022-27238MEDIUM5.4BigBlueButton version 2.4.7 (or earlier) is vulnerable to stored Cross-Site Scripting (XSS) in the private chat function...
CVE-2022-22502MEDIUM5.4IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users ...
CVE-2022-20829HIGH7.2A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those ima...
CVE-2022-20828HIGH7.2A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module cou...
CVE-2022-32209MEDIUM6.1# Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations ...
CVE-2022-30120MEDIUM6.1XSS in /dashboard/blocks/stacks/view_details/ - old browsers only. When using an older browser with built-in XSS protect...
CVE-2022-30119MEDIUM6.1XSS in /dashboard/reports/logs/view - old browsers only. When using Internet Explorer with the XSS protection disabled, ...
CVE-2022-30118MEDIUM6.1Title for CVE: XSS in /dashboard/system/express/entities/forms/save_control/[GUID]: old browsers only.Description: When ...
CVE-2022-30117CRITICAL9.1Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload whic...
CVE-2022-2121MEDIUM6.5OFFIS DCMTK's (All versions prior to 3.6.7) has a NULL pointer dereference vulnerability while processing DICOM files, w...
CVE-2022-2120CRITICAL9.8OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing ...
CVE-2022-2119CRITICAL9.8OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an at...
CVE-2022-2105CRITICAL9.1Client-side JavaScript controls may be bypassed to change user credentials and permissions without authentication, inclu...
CVE-2022-2104CRITICAL9.8The www-data (Apache web server) account is configured to run sudo with no password for many commands (including /bin/sh...
CVE-2022-2103CRITICAL9.1An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive...
CVE-2022-2102HIGH7.5Controls limiting uploads to certain file extensions may be bypassed. This could allow an attacker to intercept the init...
CVE-2022-28620CRITICAL9.8A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; a...
CVE-2022-28619HIGH7.8A potential security vulnerability has been identified in the installer of HPE Version Control Repository Manager. The v...
CVE-2022-23170CRITICAL9.8SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection vulnerability. Any SysAid environm...
CVE-2022-21829CRITICAL9.8Concrete CMS Versions 9.0.0 through 9.0.2 and 8.5.7 and below can download zip files over HTTP and execute code from tho...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now