CVEs from 2022

5,249 normalized CVEs published or assigned in this year.

Total
5,249
critical
critical 92
high
high 1,233
medium
medium 961
low
low 24
% Critical
1.8%
% with KEV
2.5%
% with exploit
3.4%

Top products

  • jdk 116
  • jre 109
  • openjdk 100
  • zulu 82
  • graalvm 74
  • cloud_secure_agent 35
  • oncommand_insight 34
  • cloud_insights_acquisition_unit 34
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-24946 high 7.5 7.5 4y ago Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of seria…
CVE-2022-27775 high 7.5 7.5 4y ago An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a conn…
CVE-2022-27782 high 7.5 7.5 4y ago libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection p…
CVE-2022-27781 high 7.5 7.5 4y ago libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make li…
CVE-2022-22786 high 7.5 7.5 4y ago The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room for Windows before version 5.10.0, fails to properly check the installation version during the update…
CVE-2022-29145 high 7.5 7.5 4y ago RHSA-2022:2202: .NET Core 3.1 security, bug fix, and enhancement update (Important)
CVE-2022-29117 high 7.5 7.5 4y ago RHSA-2022:2202: .NET Core 3.1 security, bug fix, and enhancement update (Important)
CVE-2022-23267 high 7.5 7.5 4y ago RHSA-2022:2202: .NET Core 3.1 security, bug fix, and enhancement update (Important)
CVE-2022-25647 high 7.5 7.5 4y ago Deserialization of Untrusted Data in Gson
CVE-2022-21476 high 7.5 7.5 4y ago RHSA-2022:1491: java-1.8.0-openjdk security update (Important)
CVE-2022-24763 high 7.5 7.5 4y ago PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJS…
CVE-2022-0778 high 7.5 7.5 4y ago RHSA-2022:5326: compat-openssl10 security update (Low)
CVE-2022-24464 high 7.5 7.5 4y ago RHSA-2022:0830: .NET 5.0 security and bugfix update (Important)
CVE-2022-4991 high 7.4 7.4 5d ago Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that use…
CVE-2022-47630 high 7.4 7.4 3y ago Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger d…
CVE-2022-4988 high 7.3 7.3 26d ago Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities s…
CVE-2022-35865 high 7.3 7.3 4y ago This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not required to exploit this vulnerability. The specific…
CVE-2022-0354 high 7.3 7.3 4y ago A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of …
CVE-2022-45083 high 7.2 7.2 2y ago Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.T…
CVE-2022-47599 high 7.2 7.2 3y ago Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager.This issue affects File Ma…
CVE-2022-45078 high 7.2 7.2 3y ago Improper Neutralization of Formula Elements in a CSV File vulnerability in Solwin Infotech User Blocker.This issue affects User Blocker: from n/a through 1.5.5.
CVE-2022-47605 high 7.2 7.2 3y ago Auth. SQL Injection') vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.7.0 versions.
CVE-2022-34871 high 7.2 7.2 4y ago This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the …
CVE-2022-27224 high 7.2 7.2 4y ago An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via shell metacharacters within the Network Tools sect…
CVE-2022-26826 high 7.2 7.2 4y ago Windows DNS Server Remote Code Execution Vulnerability
CVE-2022-48827 high 7.1 7.1 2y ago In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix the behavior of READ near OFFSET_MAX Dan Aloni reports: > Due to commit 8cfb9015280d ("NFS: Always provide aligned buff…
CVE-2022-49961 high 7.1 7.1 3y ago In the Linux kernel, the following vulnerability has been resolved: bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO Precision markers need to be propagated whenever we have an ARG_CON…
CVE-2022-3775 high 7.1 7.1 4y ago Moderate: grub2 security update
CVE-2022-2347 high 7.1 7.1 4y ago There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction co…
CVE-2022-37398 high 7.1 7.1 4y ago A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitrary code. Affected …
CVE-2022-22977 high 7.1 7.1 4y ago VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where…
CVE-2022-31614 high 7.0 7.0 4y ago NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it may double-free some resources. An attacker may exploit this vulnerability with other vulnerabilities t…
CVE-2022-50377 high 2y ago RHSA-2024:2394: kernel security, bug fix, and enhancement update (Important)