2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2022-36952CRITICAL9.8In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsyst...
CVE-2022-36951CRITICAL9.8In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may compromise the host by exploiting an incorrectly ...
CVE-2022-36950CRITICAL9.8In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may be able to perform remote command execution throu...
CVE-2022-24405CRITICAL9.8OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
CVE-2022-23100CRITICAL9.8OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).
CVE-2022-2310CRITICAL9.8An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x p...
CVE-2022-36129CRITICAL9.1HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthent...
CVE-2022-30274CRITICAL9.8The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio ga...
CVE-2022-30271CRITICAL9.8The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /...
CVE-2022-30270CRITICAL9.8The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This in...
CVE-2022-31207CRITICAL9.8The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic auth...
CVE-2022-31206CRITICAL9.8The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryp...
CVE-2022-30273CRITICAL9.8The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Leg...
CVE-2022-29958CRITICAL9.8JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protoco...
CVE-2022-29953CRITICAL9.8The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4...
CVE-2022-29952CRITICAL9.1Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command a...
CVE-2022-29951CRITICAL9.1JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on p...
CVE-2022-36412CRITICAL9.8In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API r...
CVE-2022-36161CRITICAL9.8Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
CVE-2022-34989CRITICAL9.8Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_passwo...
CVE-2022-34577CRITICAL9.8A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a craf...
CVE-2022-35131CRITICAL9Joplin v2.8.8 allows attackers to execute arbitrary commands via a crafted payload injected into the Node titles.
CVE-2022-34907CRITICAL9.8An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could all...
CVE-2022-35869CRITICAL9.8This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ig...
CVE-2022-24083CRITICAL9.8Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now