2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25753 | HIGH | 8.8 | 1.6% | Apr 12, 2022 | A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 E... |
| CVE-2022-25752 | CRITICAL | 9.8 | 1.4% | Apr 12, 2022 | A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 E... |
| CVE-2022-25751 | HIGH | 7.5 | 1.3% | Apr 12, 2022 | A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 E... |
| CVE-2022-25650 | MEDIUM | 6.5 | 0.6% | Apr 12, 2022 | A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.27), Mendix Applications... |
| CVE-2022-25622 | HIGH | 7.5 | 0.8% | Apr 12, 2022 | The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP s... |
| CVE-2022-23450 | CRITICAL | 9.8 | 34.9% | Apr 12, 2022 | A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manag... |
| CVE-2022-23449 | HIGH | 7.3 | 0.3% | Apr 12, 2022 | A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manag... |
| CVE-2022-23448 | HIGH | 7.8 | 0.2% | Apr 12, 2022 | A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manag... |
| CVE-2022-1302 | HIGH | 7.5 | 1.0% | Apr 12, 2022 | In the MZ Automation LibIEC61850 in versions prior to 1.5.1 an unauthenticated attacker can craft a goose message, which... |
| CVE-2022-29080 | CRITICAL | 9.8 | 2.3% | Apr 12, 2022 | The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call de... |
| CVE-2022-28347 | CRITICAL | 9.8 | 2.9% | Apr 12, 2022 | A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 befor... |
| CVE-2022-28346 | CRITICAL | 9.8 | 18.4% | Apr 12, 2022 | An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggre... |
| CVE-2022-24839 | HIGH | 7.5 | 2.0% | Apr 11, 2022 | org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises... |
| CVE-2022-24836 | HIGH | 7.5 | 3.4% | Apr 11, 2022 | Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expressio... |
| CVE-2022-24838 | CRITICAL | 9.8 | 31.6% | Apr 11, 2022 | Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails v... |
| CVE-2022-24837 | MEDIUM | 5.3 | 1.1% | Apr 11, 2022 | HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc version... |
| CVE-2022-24833 | MEDIUM | 6.1 | 1.2% | Apr 11, 2022 | PrivateBin is minimalist, open source online pastebin clone where the server has zero knowledge of pasted data. In Priva... |
| CVE-2022-24832 | MEDIUM | 6.8 | 1.6% | Apr 11, 2022 | GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD ... |
| CVE-2022-24827 | HIGH | 8.1 | 1.3% | Apr 11, 2022 | Elide is a Java library that lets you stand up a GraphQL/JSON-API web service with minimal effort. When leveraging the f... |
| CVE-2022-28779 | HIGH | 7.8 | 0.3% | Apr 11, 2022 | Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version ... |
| CVE-2022-28778 | LOW | 3.3 | 0.2% | Apr 11, 2022 | Improper access control vulnerability in Samsung Security Supporter prior to version 1.2.40.0 allows attacker to set the... |
| CVE-2022-28777 | LOW | 3.3 | 0.2% | Apr 11, 2022 | Improper access control vulnerability in Samsung Members prior to version 13.6.08.5 allows local attacker to execute cal... |
| CVE-2022-28776 | HIGH | 7.8 | 0.3% | Apr 11, 2022 | Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications ... |
| CVE-2022-28775 | LOW | 3.3 | 0.3% | Apr 11, 2022 | Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file withou... |
| CVE-2022-28544 | MEDIUM | 5.5 | 0.9% | Apr 11, 2022 | Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allow... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now