2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22278HIGH7.5A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the so...
CVE-2022-22277MEDIUM5.3A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.
CVE-2022-22276MEDIUM5.3A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.
CVE-2022-22275HIGH7.5Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy un...
CVE-2022-1507MEDIUM5.5chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a deni...
CVE-2022-27336CRITICAL9.8Seacms v11.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/weixin.php.
CVE-2022-22521HIGH7.3In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowi...
CVE-2022-22345MEDIUM4.8IBM QRadar 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J...
CVE-2022-22323MEDIUM6.5IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable t...
CVE-2022-22312MEDIUM6.5IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable t...
CVE-2022-29505HIGH7.8Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that cou...
CVE-2022-24889MEDIUM4.3Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0....
CVE-2022-24888MEDIUM4.3Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 20.0....
CVE-2022-28464CRITICAL9Apifox through 2.1.6 is vulnerable to Cross Site Scripting (XSS) which can lead to remote code execution.
CVE-2022-27905HIGH7.2In ControlUp Real-Time Agent before 8.6, an unquoted path can result in privilege escalation. An attacker would require ...
CVE-2022-27239HIGH7.8In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could le...
CVE-2022-24887MEDIUM6.1Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior to versio...
CVE-2022-24886LOW3.8Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. In versions prior to 3.1...
CVE-2022-24885LOW2.4Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. Prior to version 3.19.1,...
CVE-2022-1504MEDIUM6.1XSS in /demo/module/?module=HERE in GitHub repository microweber/microweber prior to 1.2.15. Typical impact of XSS attac...
CVE-2022-1503MEDIUM5.4A vulnerability, which was classified as problematic, has been found in GetSimple CMS. Affected by this issue is the fil...
CVE-2022-29810MEDIUM5.5The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
CVE-2022-29701HIGH7.5A lack of rate limiting in the 'forgot password' feature of Zammad v5.1.0 allows attackers to send an excessive amount o...
CVE-2022-29700HIGH7.5A lack of password length restriction in Zammad v5.1.0 allows for the creation of extremely long passwords which can cau...
CVE-2022-28085HIGH7.8A flaw was found in htmldoc commit 31f7804. A heap buffer overflow in the function pdf_write_names in ps-pdf.cxx may lea...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now