2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32562 | HIGH | 8.8 | 0.9% | Jun 13, 2022 | An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permis... |
| CVE-2022-32192 | HIGH | 7.5 | 0.9% | Jun 13, 2022 | Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor. |
| CVE-2022-32278 | HIGH | 8.8 | 1.5% | Jun 13, 2022 | XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-control... |
| CVE-2022-29257 | HIGH | 7.2 | 0.8% | Jun 13, 2022 | Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerab... |
| CVE-2022-32564 | HIGH | 7.5 | 1.1% | Jun 13, 2022 | An issue was discovered in Couchbase Server before 7.0.4. In couchbase-cli, server-eshell leaks the Cluster Manager cook... |
| CVE-2022-32560 | HIGH | 7.5 | 0.9% | Jun 13, 2022 | An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings. |
| CVE-2022-32558 | HIGH | 7.5 | 1.1% | Jun 13, 2022 | An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during ... |
| CVE-2022-32193 | MEDIUM | 6.5 | 0.7% | Jun 13, 2022 | Couchbase Server 6.6.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor. |
| CVE-2022-29247 | CRITICAL | 9.8 | 0.9% | Jun 13, 2022 | Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerab... |
| CVE-2022-31054 | HIGH | 7.5 | 1.5% | Jun 13, 2022 | Argo Events is an event-driven workflow automation framework for Kubernetes. Prior to version 1.7.1, several `HandleRout... |
| CVE-2022-31053 | CRITICAL | 9.8 | 1.0% | Jun 13, 2022 | Biscuit is an authentication and authorization token for microservices architectures. The Biscuit specification version ... |
| CVE-2022-29798 | HIGH | 7.5 | 0.6% | Jun 13, 2022 | There is a denial of service vulnerability in CV81-WDM FW versions 01.70.49.29.46. Successful exploitation could cause d... |
| CVE-2022-29797 | CRITICAL | 9.8 | 0.8% | Jun 13, 2022 | There is a buffer overflow vulnerability in CV81-WDM FW 01.70.49.29.46. Successful exploitation of this vulnerability ma... |
| CVE-2022-22259 | MEDIUM | 6.8 | 0.2% | Jun 13, 2022 | There is an improper authentication vulnerability in FLMG-10 10.0.1.0(H100SP22C00). Successful exploitation of this vuln... |
| CVE-2022-33175 | CRITICAL | 9.8 | 1.7% | Jun 13, 2022 | Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions sett... |
| CVE-2022-33174 | HIGH | 7.5 | 13.4% | Jun 13, 2022 | Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypas... |
| CVE-2022-29455 | MEDIUM | 6.1 | 23.2% | Jun 13, 2022 | DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 ve... |
| CVE-2022-28217 | MEDIUM | 6.5 | 0.7% | Jun 13, 2022 | Some part of SAP NetWeaver (EP Web Page Composer) does not sufficiently validate an XML document accepted from an untrus... |
| CVE-2022-23169 | HIGH | 7.2 | 0.4% | Jun 13, 2022 | attacker needs to craft a SQL payload. the vulnerable parameter is "agentid" must be authenticated to the admin panel. |
| CVE-2022-23168 | CRITICAL | 9.8 | 0.4% | Jun 13, 2022 | The attacker could get access to the database. The SQL injection is in the username parameter at the login panel: userna... |
| CVE-2022-23167 | CRITICAL | 9.8 | 0.4% | Jun 13, 2022 | Attacker crafts a GET request to: /mobile/downloadfile.aspx? Filename =../.. /windows/boot.ini the LFI is UNAUTHENTICATE... |
| CVE-2022-31761 | HIGH | 7.5 | 0.6% | Jun 13, 2022 | Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality... |
| CVE-2022-31760 | CRITICAL | 9.1 | 0.6% | Jun 13, 2022 | Dialog boxes can still be displayed even if the screen is locked in carrier-customized USSD services. Successful exploit... |
| CVE-2022-31757 | HIGH | 7.5 | 0.6% | Jun 13, 2022 | The setting module has a vulnerability of improper use of APIs. Successful exploitation of this vulnerability may affect... |
| CVE-2022-31754 | HIGH | 7.5 | 0.6% | Jun 13, 2022 | Logical defects in code implementation in some products. Successful exploitation of this vulnerability may affect the av... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now