2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26109 | MEDIUM | 6.5 | 0.9% | Apr 12, 2022 | When a user opens a manipulated Portable Document Format (.pdf, PDFView.x3d) received from untrusted sources in SAP 3D V... |
| CVE-2022-26108 | MEDIUM | 6.5 | 0.8% | Apr 12, 2022 | When a user opens a manipulated Picture Exchange (.pcx, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterpr... |
| CVE-2022-26107 | MEDIUM | 6.5 | 0.9% | Apr 12, 2022 | When a user opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) received from untrusted sources in SAP 3D Visual... |
| CVE-2022-26106 | MEDIUM | 6.5 | 0.9% | Apr 12, 2022 | When a user opens a manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) received from untrusted sources in SAP 3D... |
| CVE-2022-26105 | MEDIUM | 6.1 | 0.8% | Apr 12, 2022 | SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution ... |
| CVE-2022-24812 | HIGH | 8.8 | 2.2% | Apr 12, 2022 | Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a c... |
| CVE-2022-24383 | HIGH | 7.8 | 0.8% | Apr 12, 2022 | The affected product is vulnerable to an out-of-bounds read, which may result in code execution |
| CVE-2022-23703 | HIGH | 7.5 | 0.7% | Apr 12, 2022 | A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arr... |
| CVE-2022-23702 | MEDIUM | 6.7 | 0.2% | Apr 12, 2022 | A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 Servers. The vulnera... |
| CVE-2022-22541 | MEDIUM | 6.5 | 0.7% | Apr 12, 2022 | SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information... |
| CVE-2022-21228 | HIGH | 7.8 | 1.1% | Apr 12, 2022 | The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary co... |
| CVE-2022-21214 | HIGH | 7.8 | 0.9% | Apr 12, 2022 | The affected product is vulnerable to a heap-based buffer overflow, which may lead to code execution. |
| CVE-2022-21202 | MEDIUM | 5.5 | 0.7% | Apr 12, 2022 | The affected product is vulnerable to an out-of-bounds read, which may result in disclosure of sensitive information. |
| CVE-2022-21168 | MEDIUM | 5.5 | 0.7% | Apr 12, 2022 | The affected product is vulnerable due to an invalid pointer initialization, which may lead to information disclosure. |
| CVE-2022-21155 | HIGH | 7.5 | 1.0% | Apr 12, 2022 | A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing th... |
| CVE-2022-28036 | CRITICAL | 9.8 | 1.4% | Apr 12, 2022 | AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php |
| CVE-2022-28035 | CRITICAL | 9.8 | 1.4% | Apr 12, 2022 | Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php |
| CVE-2022-28034 | CRITICAL | 9.8 | 1.4% | Apr 12, 2022 | AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php |
| CVE-2022-28033 | CRITICAL | 9.8 | 5.5% | Apr 12, 2022 | Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php |
| CVE-2022-28032 | CRITICAL | 9.8 | 6.0% | Apr 12, 2022 | AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php |
| CVE-2022-27902 | — | — | — | Apr 12, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-1215. Reason: This issue was MERGED into CVE-202... |
| CVE-2022-27473 | CRITICAL | 9.8 | 1.3% | Apr 12, 2022 | SQL injection vulnerability in Topics Searching feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitr... |
| CVE-2022-27472 | CRITICAL | 9.8 | 1.3% | Apr 12, 2022 | SQL injection vulnerability in Topics Counting feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitra... |
| CVE-2022-27165 | CRITICAL | 9.8 | 1.1% | Apr 12, 2022 | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus |
| CVE-2022-27164 | CRITICAL | 9.8 | 1.1% | Apr 12, 2022 | CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now