2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-26109MEDIUM6.5When a user opens a manipulated Portable Document Format (.pdf, PDFView.x3d) received from untrusted sources in SAP 3D V...
CVE-2022-26108MEDIUM6.5When a user opens a manipulated Picture Exchange (.pcx, 2d.x3d) received from untrusted sources in SAP 3D Visual Enterpr...
CVE-2022-26107MEDIUM6.5When a user opens a manipulated Jupiter Tesselation (.jt, JTReader.x3d) received from untrusted sources in SAP 3D Visual...
CVE-2022-26106MEDIUM6.5When a user opens a manipulated Computer Graphics Metafile (.cgm, CgmCore.dll) received from untrusted sources in SAP 3D...
CVE-2022-26105MEDIUM6.1SAP NetWeaver Enterprise Portal - versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, is susceptible to script execution ...
CVE-2022-24812HIGH8.8Grafana is an open-source platform for monitoring and observability. When fine-grained access control is enabled and a c...
CVE-2022-24383HIGH7.8The affected product is vulnerable to an out-of-bounds read, which may result in code execution
CVE-2022-23703HIGH7.5A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arr...
CVE-2022-23702MEDIUM6.7A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 Servers. The vulnera...
CVE-2022-22541MEDIUM6.5SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information...
CVE-2022-21228HIGH7.8The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary co...
CVE-2022-21214HIGH7.8The affected product is vulnerable to a heap-based buffer overflow, which may lead to code execution.
CVE-2022-21202MEDIUM5.5The affected product is vulnerable to an out-of-bounds read, which may result in disclosure of sensitive information.
CVE-2022-21168MEDIUM5.5The affected product is vulnerable due to an invalid pointer initialization, which may lead to information disclosure.
CVE-2022-21155HIGH7.5A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing th...
CVE-2022-28036CRITICAL9.8AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php
CVE-2022-28035CRITICAL9.8Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php
CVE-2022-28034CRITICAL9.8AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php
CVE-2022-28033CRITICAL9.8Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php
CVE-2022-28032CRITICAL9.8AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php
CVE-2022-27902Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-1215. Reason: This issue was MERGED into CVE-202...
CVE-2022-27473CRITICAL9.8SQL injection vulnerability in Topics Searching feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitr...
CVE-2022-27472CRITICAL9.8SQL injection vulnerability in Topics Counting feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitra...
CVE-2022-27165CRITICAL9.8CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Plugin_manager_setstatus
CVE-2022-27164CRITICAL9.8CSZ CMS 1.2.2 is vulnerable to SQL Injection via cszcms_admin_Users_viewUsers

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now