2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-43519HIGH8.8Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow ...
CVE-2022-37934HIGH7.5A potential security vulnerability has been identified in HPE OfficeConnect 1820, and 1850 switch series. The vulnerabil...
CVE-2022-37933HIGH7.8A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnera...
CVE-2022-48217HIGH8.1The tf_remapper_node component 1.1.1 for Robot Operating System (ROS) allows attackers, who control the source code of a...
CVE-2022-43920HIGH8.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 could allow an authenticated user to gain privilege...
CVE-2022-25926HIGH7.8Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due t...
CVE-2022-48216HIGH7.5Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds.
CVE-2022-46081HIGH7.5In Garmin Connect 4.61, terminating a LiveTrack session wouldn't prevent the LiveTrack API from continued exposure of pr...
CVE-2022-42435HIGH8.8 IBM Business Automation Workflow 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2...
CVE-2022-38723HIGH8.6Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
CVE-2022-2967HIGH7.5Prosys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not suffi...
CVE-2022-44036HIGH7.2In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for adm...
CVE-2022-36943HIGH8.1SSZipArchive versions 2.5.3 and older contain an arbitrary file write vulnerability due to lack of sanitization on paths...
CVE-2022-32664HIGH8.8In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote esc...
CVE-2022-32635HIGH7.8In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...
CVE-2022-23506HIGH7.5Spinnaker is an open source, multi-cloud continuous delivery platform for releasing software changes, and Spinnaker's Ro...
CVE-2022-45867HIGH7.2MyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with hig...
CVE-2022-45143HIGH7.5The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, mess...
CVE-2022-39947HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC versio...
CVE-2022-35845HIGH8.8Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE...
CVE-2022-38766HIGH8.1The remote keyless system on Renault ZOE 2021 vehicles sends 433.92 MHz RF signals from the same Rolling Codes set for e...
CVE-2022-4871HIGH7.2A vulnerability classified as problematic was found in ummmmm nflpick-em.com up to 2.2.x. This vulnerability affects the...
CVE-2022-47908HIGH7.8Stack-based buffer overflow vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the inform...
CVE-2022-47317HIGH7.8Out-of-bounds write vulnerability in V-Server v4.0.12.0 and earlier allows a local attacker to obtain the information an...
CVE-2022-46360HIGH7.8Out-of-bounds read vulnerability in V-SFT v6.1.7.0 and earlier and TELLUS v4.0.12.0 and earlier allows a local attacker ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now