2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22550 | MEDIUM | 6.7 | 0.2% | Apr 12, 2022 | Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local atta... |
| CVE-2022-22549 | HIGH | 8.1 | 0.6% | Apr 12, 2022 | Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated remote attacker could ... |
| CVE-2022-28795 | MEDIUM | 6.5 | 1.0% | Apr 12, 2022 | A vulnerability within the Avira Password Manager Browser Extensions provided a potential loophole where, if a user visi... |
| CVE-2022-28773 | HIGH | 7.5 | 1.4% | Apr 12, 2022 | Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash... |
| CVE-2022-28772 | HIGH | 7.5 | 1.4% | Apr 12, 2022 | By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions ... |
| CVE-2022-28770 | MEDIUM | 6.1 | 0.8% | Apr 12, 2022 | Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated a... |
| CVE-2022-28397 | CRITICAL | 9.8 | 3.4% | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitr... |
| CVE-2022-28396 | — | — | — | Apr 12, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-28216 | MEDIUM | 6.1 | 0.8% | Apr 12, 2022 | SAP BusinessObjects Business Intelligence Platform (BI Workspace) - version 420, is susceptible to a Cross-Site Scriptin... |
| CVE-2022-28215 | MEDIUM | 4.7 | 0.8% | Apr 12, 2022 | SAP NetWeaver ABAP Server and ABAP Platform - versions 740, 750, 787, allows an unauthenticated attacker to redirect use... |
| CVE-2022-28213 | HIGH | 8.1 | 12.1% | Apr 12, 2022 | When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does n... |
| CVE-2022-27952 | CRITICAL | 9.8 | 2.1% | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbit... |
| CVE-2022-27671 | MEDIUM | 6.5 | 1.2% | Apr 12, 2022 | A CSRF token visible in the URL may possibly lead to information disclosure vulnerability. |
| CVE-2022-27670 | MEDIUM | 6.5 | 0.9% | Apr 12, 2022 | SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywh... |
| CVE-2022-27669 | HIGH | 7.5 | 0.9% | Apr 12, 2022 | An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - v... |
| CVE-2022-27667 | HIGH | 7.5 | 1.3% | Apr 12, 2022 | Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version ... |
| CVE-2022-27657 | LOW | 2.7 | 2.4% | Apr 12, 2022 | A highly privileged remote attacker, can gain unauthorized access to display contents of restricted directories by explo... |
| CVE-2022-27655 | MEDIUM | 6.5 | 1.1% | Apr 12, 2022 | When a user opens a manipulated Universal 3D (.u3d, 3difr.x3d) received from untrusted sources in SAP 3D Visual Enterpri... |
| CVE-2022-27654 | MEDIUM | 6.5 | 1.1% | Apr 12, 2022 | When a user opens a manipulated Photoshop Document (.psd, 2d.x3d) received from untrusted sources in SAP 3D Visual Enter... |
| CVE-2022-27263 | CRITICAL | 9.8 | 3.1% | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary ... |
| CVE-2022-27262 | CRITICAL | 9.8 | 2.1% | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary... |
| CVE-2022-27261 | HIGH | 7.5 | 1.3% | Apr 12, 2022 | An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the sa... |
| CVE-2022-27260 | CRITICAL | 9.8 | 3.0% | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbi... |
| CVE-2022-27140 | CRITICAL | 9.8 | 2.6% | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute... |
| CVE-2022-27139 | CRITICAL | 9.8 | 3.8% | Apr 12, 2022 | An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now