2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22550MEDIUM6.7Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local atta...
CVE-2022-22549HIGH8.1Dell PowerScale OneFS, 8.2.x-9.3.x, contains a Improper Certificate Validation. A unauthenticated remote attacker could ...
CVE-2022-28795MEDIUM6.5A vulnerability within the Avira Password Manager Browser Extensions provided a potential loophole where, if a user visi...
CVE-2022-28773HIGH7.5Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager, the application may crash...
CVE-2022-28772HIGH7.5By overlong input values an attacker may force overwrite of the internal program stack in SAP Web Dispatcher - versions ...
CVE-2022-28770MEDIUM6.1Due to insufficient input validation, SAPUI5 library(vbm) - versions 750, 753, 754, 755, 75, allows an unauthenticated a...
CVE-2022-28397CRITICAL9.8An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitr...
CVE-2022-28396Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-28216MEDIUM6.1SAP BusinessObjects Business Intelligence Platform (BI Workspace) - version 420, is susceptible to a Cross-Site Scriptin...
CVE-2022-28215MEDIUM4.7SAP NetWeaver ABAP Server and ABAP Platform - versions 740, 750, 787, allows an unauthenticated attacker to redirect use...
CVE-2022-28213HIGH8.1When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does n...
CVE-2022-27952CRITICAL9.8An arbitrary file upload vulnerability in the file upload module of PayloadCMS v0.15.0 allows attackers to execute arbit...
CVE-2022-27671MEDIUM6.5A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.
CVE-2022-27670MEDIUM6.5SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywh...
CVE-2022-27669HIGH7.5An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver Application Server for Java - v...
CVE-2022-27667HIGH7.5Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management Console (CMC) - version ...
CVE-2022-27657LOW2.7A highly privileged remote attacker, can gain unauthorized access to display contents of restricted directories by explo...
CVE-2022-27655MEDIUM6.5When a user opens a manipulated Universal 3D (.u3d, 3difr.x3d) received from untrusted sources in SAP 3D Visual Enterpri...
CVE-2022-27654MEDIUM6.5When a user opens a manipulated Photoshop Document (.psd, 2d.x3d) received from untrusted sources in SAP 3D Visual Enter...
CVE-2022-27263CRITICAL9.8An arbitrary file upload vulnerability in the file upload module of Strapi v4.1.5 allows attackers to execute arbitrary ...
CVE-2022-27262CRITICAL9.8An arbitrary file upload vulnerability in the file upload module of Skipper v0.9.1 allows attackers to execute arbitrary...
CVE-2022-27261HIGH7.5An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the sa...
CVE-2022-27260CRITICAL9.8An arbitrary file upload vulnerability in the file upload component of ButterCMS v1.2.8 allows attackers to execute arbi...
CVE-2022-27140CRITICAL9.8An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute...
CVE-2022-27139CRITICAL9.8An arbitrary file upload vulnerability in the file upload module of Ghost v4.39.0 allows attackers to execute arbitrary ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now