LiveActive security incident?Get immediate response
CVE archive

2022 CVE Archive

Browse CVE records published in 2022 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 26423 matching CVEs · Page 13 of 529.

High · CVSS 7.8

CVE-2022-38583: On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or...

On versions of Sage 300 2017 - 2022 (6.4.x - 6.9.x) which are setup in a "Windows Peer-to-Peer Network" or "Client Server Network" configuration, a low-privileged Sage 300 workstation user could abuse their access to the "SharedData" folder on the connected Sage 300 server to view and/or modify the credentials associated with Sage 300 users and SQL accounts to impersonate users and/or access the SQL database as a system administrator. With system administrator-level access to the Sage 300 MS SQL database it would be possible to create, update, and delete all records associated with the program and, depending on the configuration, execute code on the underlying database server.

Published Apr 28, 2023 · Updated Jul 9, 2026

Medium · CVSS 5.3

CVE-2022-37774: There is a broken access control vulnerability in the Maarch RM 2.8.3 solution.

There is a broken access control vulnerability in the Maarch RM 2.8.3 solution. When accessing some specific document (pdf, email) from an archive, a preview is proposed by the application. This preview generates a URL including an md5 hash of the file accessed. The document's URL (https://{url}/tmp/{MD5 hash of the document}) is then accessible without authentication.

Published Nov 22, 2022 · Updated Jul 9, 2026

Critical · CVSS 9

CVE-2022-37720: Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS).

Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low privileged user such as an author or publisher, injects a crafted html and javascript payload in a blog post, leading to full admin account takeover or privilege escalation when the malicious blog post is loaded in the victim's browser.

Published Nov 25, 2022 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2022-37700: Zentao Demo15 is vulnerable to Directory Traversal.

Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig.

Published Sep 19, 2022 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2022-37146: The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on in...

The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentication provider. Login attempts for valid, unlocked users configured to use PlexTrac as their authentication provider take significantly longer than those for invalid users, allowing for valid users to be enumerated by an unauthenticated remote attacker. Note that the lockout policy implemented in Plextrac version 1.17.0 makes it impossible to distinguish between valid, locked user accounts and user accounts that do not exist, but does not prevent valid, unlocked users from being enumerated.

Published Sep 8, 2022 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2022-37145: The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accou...

The PlexTrac platform prior to version 1.17.0 does not restrict excessive authentication attempts for accounts configured to use the PlexTrac authentication provider. An unauthenticated remote attacker could perform a bruteforce attack on the login page with no time or attempt limitation in an attempt to obtain valid credentials for the platform users configured to use the PlexTrac authentication provider.

Published Sep 8, 2022 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2022-36640: influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticat...

influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization."

Published Sep 2, 2022 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2022-36551: A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition...

A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.0 and earlier allows an authenticated user to access arbitrary files on the system. Furthermore, self-registration is enabled by default in these versions of Label Studio enabling a remote attacker to create a new account and then exploit the SSRF.

Published Oct 3, 2022 · Updated Jul 9, 2026