2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-20741MEDIUM5.4A vulnerability in the web-based management interface of the Network Diagrams application for Cisco Secure Network Analy...
CVE-2022-20675MEDIUM5.3A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cis...
CVE-2022-20665MEDIUM6.7A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affe...
CVE-2022-26850MEDIUM4.3When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers c...
CVE-2022-24822HIGH7.5Podium is a library for building micro frontends. @podium/layout is a module for building a Podium layout server, and @p...
CVE-2022-20784MEDIUM5.3A vulnerability in the Web-Based Reputation Score (WBRS) engine of Cisco AsyncOS Software for Cisco Web Security Applian...
CVE-2022-22410HIGH7.2IBM Watson Query with Cloud Pak for Data as a Service could allow an authenticated user to obtain sensitive information ...
CVE-2022-27110MEDIUM5.4OrangeHRM 4.10 is vulnerable to a Host header injection redirect via viewPersonalDetails endpoint.
CVE-2022-27109MEDIUM5.4OrangeHRM 4.10 suffers from a Referer header injection redirect vulnerability.
CVE-2022-27108MEDIUM4.3OrangeHRM 4.10 is vulnerable to Insecure Direct Object Reference (IDOR) via the end point symfony/web/index.php/time/cre...
CVE-2022-27107MEDIUM5.4OrangeHRM 4.10 is vulnerable to Stored XSS in the "Share Video" section under "OrangeBuzz" via the GET/POST "createVideo...
CVE-2022-24793HIGH7.5PJSIP is a free and open source multimedia communication library written in C. A buffer overflow vulnerability in versio...
CVE-2022-24786CRITICAL9.8PJSIP is a free and open source multimedia communication library written in C. PJSIP versions 2.12 and prior do not pars...
CVE-2022-1253CRITICAL9.8Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established...
CVE-2022-1240HIGH7.8Heap buffer overflow in libr/bin/format/mach0/mach0.c in GitHub repository radareorg/radare2 prior to 5.8.6. If address ...
CVE-2022-23440HIGH7.8A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versi...
CVE-2022-1238HIGH7.8Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability...
CVE-2022-1237HIGH7.8Improper Validation of Array Index in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap ove...
CVE-2022-23446MEDIUM4.4A improper control of a resource through its lifetime in Fortinet FortiEDR version 5.0.3 and earlier allows attacker to ...
CVE-2022-23441CRITICAL9.1A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow ...
CVE-2022-1234MEDIUM6.1XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the poten...
CVE-2022-1248HIGH7.3A vulnerability was found in SAP Information System 1.0 which has been rated as critical. Affected by this issue is the ...
CVE-2022-26110HIGH8.8An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authen...
CVE-2022-26953HIGH7.5Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow. An attacker can supply a string in the page par...
CVE-2022-26952HIGH7.5Digi Passport Firmware through 1.5.1,1 is affected by a buffer overflow in the function for building the Location header...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now