CVEs from 2022

5,244 normalized CVEs published or assigned in this year.

Total
5,244
critical
critical 92
high
high 1,233
medium
medium 961
low
low 24
% Critical
1.8%
% with KEV
2.5%
% with exploit
3.4%

Top products

  • jdk 116
  • jre 109
  • openjdk 100
  • zulu 82
  • graalvm 74
  • cloud_secure_agent 35
  • oncommand_insight 34
  • cloud_insights_acquisition_unit 34
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-24946 high 7.5 7.5 4y ago Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of seria…
CVE-2022-27775 high 7.5 7.5 4y ago An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a conn…
CVE-2022-27781 high 7.5 7.5 4y ago libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make li…
CVE-2022-27782 high 7.5 7.5 4y ago libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection p…
CVE-2022-22786 high 7.5 7.5 4y ago The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update…
CVE-2022-29145 high 7.5 7.5 4y ago RHSA-2022:2202: .NET Core 3.1 security, bug fix, and enhancement update (Important)
CVE-2022-29117 high 7.5 7.5 4y ago RHSA-2022:2202: .NET Core 3.1 security, bug fix, and enhancement update (Important)
CVE-2022-23267 high 7.5 7.5 4y ago RHSA-2022:2202: .NET Core 3.1 security, bug fix, and enhancement update (Important)
CVE-2022-25647 high 7.5 7.5 4y ago Deserialization of Untrusted Data in Gson
CVE-2022-21476 high 7.5 7.5 4y ago RHSA-2022:1491: java-1.8.0-openjdk security update (Important)
CVE-2022-24763 high 7.5 7.5 4y ago PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJS…
CVE-2022-0778 high 7.5 7.5 4y ago RHSA-2022:5326: compat-openssl10 security update (Low)
CVE-2022-24464 high 7.5 7.5 4y ago RHSA-2022:0830: .NET 5.0 security and bugfix update (Important)
CVE-2022-4991 high 7.4 7.4 5d ago Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that use…
CVE-2022-47630 high 7.4 7.4 3y ago Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger d…
CVE-2022-4988 high 7.3 7.3 26d ago Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities s…
CVE-2022-35865 high 7.3 7.3 4y ago This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not required to exploit this vulnerability. The specific…
CVE-2022-0354 high 7.3 7.3 4y ago A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of …
CVE-2022-45083 high 7.2 7.2 2y ago Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.T…
CVE-2022-47599 high 7.2 7.2 3y ago Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager.This issue affects File Ma…
CVE-2022-45078 high 7.2 7.2 3y ago Improper Neutralization of Formula Elements in a CSV File vulnerability in Solwin Infotech User Blocker.This issue affects User Blocker: from n/a through 1.5.5.
CVE-2022-47605 high 7.2 7.2 3y ago Auth. SQL Injection') vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.7.0 versions.
CVE-2022-34871 high 7.2 7.2 4y ago This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the …
CVE-2022-27224 high 7.2 7.2 4y ago An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via shell metacharacters within the Network Tools sect…
CVE-2022-26826 high 7.2 7.2 4y ago Windows DNS Server Remote Code Execution Vulnerability
CVE-2022-48827 high 7.1 7.1 2y ago In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix the behavior of READ near OFFSET_MAX Dan Aloni reports: > Due to commit 8cfb9015280d ("NFS: Always provide aligned buff…
CVE-2022-49961 high 7.1 7.1 3y ago In the Linux kernel, the following vulnerability has been resolved: bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO Precision markers need to be propagated whenever we have an ARG_CON…
CVE-2022-3775 high 7.1 7.1 4y ago Moderate: grub2 security update
CVE-2022-2347 high 7.1 7.1 4y ago There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction co…
CVE-2022-37398 high 7.1 7.1 4y ago A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitrary code. Affected …
CVE-2022-22977 high 7.1 7.1 4y ago VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where…
CVE-2022-31614 high 7.0 7.0 4y ago NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it may double-free some resources. An attacker may exploit this vulnerability with other vulnerabilities t…
CVE-2022-45809 low 3.7 3.7 3y ago Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.0.0.
CVE-2022-39399 low 3.7 3.7 4y ago RHSA-2022:7012: java-11-openjdk security and bug fix update (Moderate)
CVE-2022-21624 low 3.7 3.7 4y ago RHSA-2023:0128: java-1.8.0-ibm security update (Moderate)
CVE-2022-21619 low 3.7 3.7 4y ago RHSA-2023:0128: java-1.8.0-ibm security update (Moderate)
CVE-2022-45819 low 3.5 3.5 2y ago Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n/a through 1.17.1.
CVE-2022-3358 low 3.5 4y ago Low: openssl security and bug fix update
CVE-2022-24101 low 3.3 3.3 4y ago Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensit…
CVE-2022-27227 low 2.5 In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an…
CVE-2022-29458 low 2.5 10mo ago ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
CVE-2022-45063 low 2.5 1y ago Low: xterm security update
CVE-2022-48554 low 2.5 2y ago File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.
CVE-2022-43552 low 2.5 3y ago A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operat…
CVE-2022-28805 low 2.5 3y ago Low: lua security update
CVE-2022-36227 low 2.5 3y ago RHSA-2023:3018: libarchive security update (Low)
CVE-2022-1615 low 2.5 3y ago RHSA-2023:2987: samba security, bug fix, and enhancement update (Low)
CVE-2022-35252 low 2.5 3y ago When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. …
CVE-2022-41862 low 2.5 3y ago RHSA-2023:7016: libpq security update (Low)
CVE-2022-2990 low 2.5 4y ago RHSA-2022:7822: container-tools:rhel8 security, bug fix, and enhancement update (Low)
CVE-2022-1122 low 2.5 4y ago RHSA-2022:7645: openjpeg2 security update (Low)
CVE-2022-24735 low 2.5 4y ago RHSA-2022:7541: redis:6 security, bug fix, and enhancement update (Low)
CVE-2022-23645 low 2.5 4y ago RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low)
CVE-2022-0897 low 2.5 4y ago RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low)
CVE-2022-2211 low 2.5 4y ago RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low)
CVE-2022-24736 low 2.5 4y ago RHSA-2022:7541: redis:6 security, bug fix, and enhancement update (Low)
CVE-2022-50377 high 2y ago RHSA-2024:2394: kernel security, bug fix, and enhancement update (Important)