2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25753HIGH8.8A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 E...
CVE-2022-25752CRITICAL9.8A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 E...
CVE-2022-25751HIGH7.5A vulnerability has been identified in SCALANCE X302-7 EEC (230V), SCALANCE X302-7 EEC (230V, coated), SCALANCE X302-7 E...
CVE-2022-25650MEDIUM6.5A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.27), Mendix Applications...
CVE-2022-25622HIGH7.5The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP s...
CVE-2022-23450CRITICAL9.8A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manag...
CVE-2022-23449HIGH7.3A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manag...
CVE-2022-23448HIGH7.8A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manag...
CVE-2022-1302HIGH7.5In the MZ Automation LibIEC61850 in versions prior to 1.5.1 an unauthenticated attacker can craft a goose message, which...
CVE-2022-29080CRITICAL9.8The npm-dependency-versions package through 0.3.0 for Node.js allows command injection if an attacker is able to call de...
CVE-2022-28347CRITICAL9.8A SQL injection issue was discovered in QuerySet.explain() in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 befor...
CVE-2022-28346CRITICAL9.8An issue was discovered in Django 2.2 before 2.2.28, 3.2 before 3.2.13, and 4.0 before 4.0.4. QuerySet.annotate(), aggre...
CVE-2022-24839HIGH7.5org.cyberneko.html is an html parser written in Java. The fork of `org.cyberneko.html` used by Nokogiri (Rubygem) raises...
CVE-2022-24836HIGH7.5Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expressio...
CVE-2022-24838CRITICAL9.8Nextcloud Calendar is a calendar application for the nextcloud framework. SMTP Command Injection in Appointment Emails v...
CVE-2022-24837MEDIUM5.3HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc version...
CVE-2022-24833MEDIUM6.1PrivateBin is minimalist, open source online pastebin clone where the server has zero knowledge of pasted data. In Priva...
CVE-2022-24832MEDIUM6.8GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD ...
CVE-2022-24827HIGH8.1Elide is a Java library that lets you stand up a GraphQL/JSON-API web service with minimal effort. When leveraging the f...
CVE-2022-28779HIGH7.8Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version ...
CVE-2022-28778LOW3.3Improper access control vulnerability in Samsung Security Supporter prior to version 1.2.40.0 allows attacker to set the...
CVE-2022-28777LOW3.3Improper access control vulnerability in Samsung Members prior to version 13.6.08.5 allows local attacker to execute cal...
CVE-2022-28776HIGH7.8Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications ...
CVE-2022-28775LOW3.3Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file withou...
CVE-2022-28544MEDIUM5.5Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allow...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now