2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-32562HIGH8.8An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permis...
CVE-2022-32192HIGH7.5Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
CVE-2022-32278HIGH8.8XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-control...
CVE-2022-29257HIGH7.2Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerab...
CVE-2022-32564HIGH7.5An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cook...
CVE-2022-32560HIGH7.5An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.
CVE-2022-32558HIGH7.5An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during ...
CVE-2022-32193MEDIUM6.5Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
CVE-2022-29247CRITICAL9.8Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerab...
CVE-2022-31054HIGH7.5Argo Events is an event-driven workflow automation framework for Kubernetes. Prior to version 1.7.1, several `HandleRout...
CVE-2022-31053CRITICAL9.8Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version ...
CVE-2022-29798HIGH7.5There is a denial of service vulnerability in CV81-WDM FW versions 01.70.49.29.46. Successful exploitation could cause d...
CVE-2022-29797CRITICAL9.8There is a buffer overflow vulnerability in CV81-WDM FW 01.70.49.29.46. Successful exploitation of this vulnerability ma...
CVE-2022-22259MEDIUM6.8There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00). Successful exploitation of this vuln...
CVE-2022-33175CRITICAL9.8Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions sett...
CVE-2022-33174HIGH7.5Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypas...
CVE-2022-29455MEDIUM6.1DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 ve...
CVE-2022-28217MEDIUM6.5Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrus...
CVE-2022-23169HIGH7.2attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel.
CVE-2022-23168CRITICAL9.8The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: userna...
CVE-2022-23167CRITICAL9.8Attacker crafts a GET request to: /mobile/downloadfile.aspx? Filename =../.. /windows/boot.ini the LFI is UNAUTHENTICATE...
CVE-2022-31761HIGH7.5Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality...
CVE-2022-31760CRITICAL9.1Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploit...
CVE-2022-31757HIGH7.5The setting module has a vulnerability of improper use of APIs. Successful exploitation of this vulnerability may affect...
CVE-2022-31754HIGH7.5Logical defects in code implementation in some products. Successful exploitation of this vulnerability may affect the av...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now