CVEs from 2022
Total
5,236
critical
critical 92
high
high 1,236
medium
medium 953
low
low 24
% Critical
1.8%
% with KEV
2.5%
% with exploit
3.4%
Top vendors
- oracle 616
- netapp 438
- microsoft 165
- omron 109
- azul 82
- schneider-electric 33
- mitsubishielectric 32
- siemens 10
Top products
- jdk 116
- jre 109
- openjdk 100
- zulu 82
- graalvm 74
- cloud_secure_agent 35
- oncommand_insight 34
- cloud_insights_acquisition_unit 34
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29145 | high | 7.5 | 7.5 | 4y ago | RHSA-2022:2202: .NET Core 3.1 security, bug fix, and enhancement update (Important) | |||
| CVE-2022-29117 | high | 7.5 | 7.5 | 4y ago | RHSA-2022:2202: .NET Core 3.1 security, bug fix, and enhancement update (Important) | |||
| CVE-2022-23267 | high | 7.5 | 7.5 | 4y ago | RHSA-2022:2202: .NET Core 3.1 security, bug fix, and enhancement update (Important) | |||
| CVE-2022-25647 | high | 7.5 | 7.5 | 4y ago | Deserialization of Untrusted Data in Gson | |||
| CVE-2022-21476 | high | 7.5 | 7.5 | 4y ago | unknown in jre11-openjdk, jdk11-openjdk, jre11-openjdk-headless | |||
| CVE-2022-24763 | high | 7.5 | 7.5 | 4y ago | PJSIP is a free and open source multimedia communication library written in the C language. Versions 2.12 and prior contain a denial-of-service vulnerability that affects PJSIP users that consume PJS… | |||
| CVE-2022-0778 | high | 7.5 | 7.5 | 4y ago | RHSA-2022:5326: compat-openssl10 security update (Low) | |||
| CVE-2022-24464 | high | 7.5 | 7.5 | 4y ago | RHSA-2022:0830: .NET 5.0 security and bugfix update (Important) | |||
| CVE-2022-4991 | high | 7.4 | 7.4 | 6d ago | Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that use… | |||
| CVE-2022-47630 | high | 7.4 | 7.4 | 3y ago | Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext and auth_nvctr. Attackers might be able to trigger d… | |||
| CVE-2022-4988 | high | 7.3 | 7.3 | 27d ago | Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities s… | |||
| CVE-2022-35865 | high | 7.3 | 7.3 | 4y ago | This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not required to exploit this vulnerability. The specific… | |||
| CVE-2022-0354 | high | 7.3 | 7.3 | 4y ago | A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of … | |||
| CVE-2022-45083 | high | 7.2 | 7.2 | 2y ago | Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.T… | |||
| CVE-2022-47599 | high | 7.2 | 7.2 | 3y ago | Deserialization of Untrusted Data vulnerability in File Manager by Bit Form Team File Manager – 100% Free & Open Source File Manager Plugin for WordPress | Bit File Manager.This issue affects File Ma… | |||
| CVE-2022-45078 | high | 7.2 | 7.2 | 3y ago | Improper Neutralization of Formula Elements in a CSV File vulnerability in Solwin Infotech User Blocker.This issue affects User Blocker: from n/a through 1.5.5. | |||
| CVE-2022-47605 | high | 7.2 | 7.2 | 3y ago | Auth. SQL Injection') vulnerability in Kunal Nagar Custom 404 Pro plugin <= 3.7.0 versions. | |||
| CVE-2022-34871 | high | 7.2 | 7.2 | 4y ago | This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the … | |||
| CVE-2022-27224 | high | 7.2 | 7.2 | 4y ago | An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via shell metacharacters within the Network Tools sect… | |||
| CVE-2022-26826 | high | 7.2 | 7.2 | 4y ago | Windows DNS Server Remote Code Execution Vulnerability | |||
| CVE-2022-48827 | high | 7.1 | 7.1 | 2y ago | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix the behavior of READ near OFFSET_MAX Dan Aloni reports: > Due to commit 8cfb9015280d ("NFS: Always provide aligned buff… | |||
| CVE-2022-49961 | high | 7.1 | 7.1 | 3y ago | In the Linux kernel, the following vulnerability has been resolved: bpf: Do mark_chain_precision for ARG_CONST_ALLOC_SIZE_OR_ZERO Precision markers need to be propagated whenever we have an ARG_CON… | |||
| CVE-2022-3775 | high | 7.1 | 7.1 | 4y ago | Moderate: grub2 security update | |||
| CVE-2022-2347 | high | 7.1 | 7.1 | 4y ago | There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction co… | |||
| CVE-2022-37398 | high | 7.1 | 7.1 | 4y ago | A stack-based buffer overflow vulnerability was found inside ADM when using WebDAV due to the lack of data size validation. An attacker can exploit this vulnerability to run arbitrary code. Affected … | |||
| CVE-2022-22977 | high | 7.1 | 7.1 | 4y ago | VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where… | |||
| CVE-2022-31614 | high | 7.0 | 7.0 | 4y ago | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it may double-free some resources. An attacker may exploit this vulnerability with other vulnerabilities t… | |||
| CVE-2022-45809 | low | 3.7 | 3.7 | 3y ago | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Ricard Torres Thumbs Rating.This issue affects Thumbs Rating: from n/a through 5.0.0. | |||
| CVE-2022-21624 | low | 3.7 | 3.7 | 4y ago | RHSA-2023:0128: java-1.8.0-ibm security update (Moderate) | |||
| CVE-2022-39399 | low | 3.7 | 3.7 | 4y ago | RHSA-2022:7012: java-11-openjdk security and bug fix update (Moderate) | |||
| CVE-2022-21619 | low | 3.7 | 3.7 | 4y ago | RHSA-2023:0128: java-1.8.0-ibm security update (Moderate) | |||
| CVE-2022-45819 | low | 3.5 | 3.5 | 2y ago | Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n/a through 1.17.1. | |||
| CVE-2022-3358 | low | — | 3.5 | 4y ago | Low: openssl security and bug fix update | |||
| CVE-2022-24101 | low | 3.3 | 3.3 | 4y ago | Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensit… | |||
| CVE-2022-27227 | low | — | 2.5 | — | In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an… | |||
| CVE-2022-29458 | low | — | 2.5 | 10mo ago | ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library. | |||
| CVE-2022-45063 | low | — | 2.5 | 1y ago | Low: xterm security update | |||
| CVE-2022-48554 | low | — | 2.5 | 2y ago | File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project. | |||
| CVE-2022-1615 | low | — | 2.5 | 3y ago | RHSA-2023:2987: samba security, bug fix, and enhancement update (Low) | |||
| CVE-2022-28805 | low | — | 2.5 | 3y ago | Low: lua security update | |||
| CVE-2022-43552 | low | — | 2.5 | 3y ago | A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operat… | |||
| CVE-2022-36227 | low | — | 2.5 | 3y ago | RHSA-2023:3018: libarchive security update (Low) | |||
| CVE-2022-35252 | low | — | 2.5 | 3y ago | When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. … | |||
| CVE-2022-41862 | low | — | 2.5 | 3y ago | RHSA-2023:7016: libpq security update (Low) | |||
| CVE-2022-24735 | low | — | 2.5 | 4y ago | RHSA-2022:7541: redis:6 security, bug fix, and enhancement update (Low) | |||
| CVE-2022-2990 | low | — | 2.5 | 4y ago | RHSA-2022:7822: container-tools:rhel8 security, bug fix, and enhancement update (Low) | |||
| CVE-2022-0897 | low | — | 2.5 | 4y ago | RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low) | |||
| CVE-2022-1122 | low | — | 2.5 | 4y ago | RHSA-2022:7645: openjpeg2 security update (Low) | |||
| CVE-2022-2211 | low | — | 2.5 | 4y ago | RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low) | |||
| CVE-2022-23645 | low | — | 2.5 | 4y ago | RHSA-2022:7472: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Low) | |||
| CVE-2022-24736 | low | — | 2.5 | 4y ago | RHSA-2022:7541: redis:6 security, bug fix, and enhancement update (Low) | |||
| CVE-2022-50377 | high | — | — | 2y ago | RHSA-2024:2394: kernel security, bug fix, and enhancement update (Important) |