CVEs from 2022

5,236 normalized CVEs published or assigned in this year.

Total
5,236
critical
critical 92
high
high 1,236
medium
medium 953
low
low 24
% Critical
1.8%
% with KEV
2.5%
% with exploit
3.4%

Top products

  • jdk 116
  • jre 109
  • openjdk 100
  • zulu 82
  • graalvm 74
  • cloud_secure_agent 35
  • oncommand_insight 34
  • cloud_insights_acquisition_unit 34
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-48768 unknown In the Linux kernel, the following vulnerability has been resolved: tracing/histogram: Fix a potential memory leak for kstrdup() kfree() is missing on an error path to free the memory allocated by …
CVE-2022-48778 unknown In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: gpmi: don't leak PM reference in error path If gpmi_nfc_apply_timings() fails, the PM runtime usage counter must be…
CVE-2022-48772 unknown In the Linux kernel, the following vulnerability has been resolved: media: lgdt3306a: Add a check against null-pointer-def The driver should check whether the client provides the platform_data. Th…
CVE-2022-48774 unknown In the Linux kernel, the following vulnerability has been resolved: dmaengine: ptdma: Fix the error handling path in pt_core_init() In order to free resources correctly in the error handling path o…
CVE-2022-48775 unknown In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Fix memory leak in vmbus_add_channel_kobj kobject_init_and_add() takes reference even when it fails. Accordin…
CVE-2022-48776 unknown In the Linux kernel, the following vulnerability has been resolved: mtd: parsers: qcom: Fix missing free for pparts in cleanup Mtdpart doesn't free pparts when a cleanup function is declared. Add m…
CVE-2022-48777 unknown In the Linux kernel, the following vulnerability has been resolved: mtd: parsers: qcom: Fix kernel panic on skipped partition In the event of a skipped partition (case when the entry name is empty)…
CVE-2022-48779 unknown In the Linux kernel, the following vulnerability has been resolved: net: mscc: ocelot: fix use-after-free in ocelot_vlan_del() ocelot_vlan_member_del() will free the struct ocelot_bridge_vlan, so i…
CVE-2022-48780 unknown In the Linux kernel, the following vulnerability has been resolved: net/smc: Avoid overwriting the copies of clcsock callback functions The callback functions of clcsock will be saved and replaced …
CVE-2022-48785 unknown In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: use rcu-safe version of ipv6_get_lladdr() Some time ago 8965779d2c0e ("ipv6,mcast: always hold idev->lock before mca…
CVE-2022-48782 unknown In the Linux kernel, the following vulnerability has been resolved: mctp: fix use after free Clang static analysis reports this problem route.c:425:4: warning: Use of memory after it is freed tra…
CVE-2022-48783 unknown In the Linux kernel, the following vulnerability has been resolved: net: dsa: lantiq_gswip: fix use after free in gswip_remove() of_node_put(priv->ds->slave_mii_bus->dev.of_node) should be done bef…
CVE-2022-48784 unknown In the Linux kernel, the following vulnerability has been resolved: cfg80211: fix race in netlink owner interface destruction My previous fix here to fix the deadlock left a race where the exact sa…
CVE-2022-48787 unknown In the Linux kernel, the following vulnerability has been resolved: iwlwifi: fix use-after-free If no firmware was present at all (or, presumably, all of the firmware files failed to parse), we end…
CVE-2022-48788 unknown In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: fix possible use-after-free in transport error_recovery work While nvme_rdma_submit_async_event_work is checking the c…
CVE-2022-48789 unknown In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix possible use-after-free in transport error_recovery work While nvme_tcp_submit_async_event_work is checking the ctr…
CVE-2022-48790 unknown In the Linux kernel, the following vulnerability has been resolved: nvme: fix a possible use-after-free in controller reset during load Unlike .queue_rq, in .submit_async_event drivers may not chec…
CVE-2022-48791 unknown In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted TMF sas_task Currently a use-after-free may occur if a TMF sas_task is aborted befor…
CVE-2022-48792 unknown In the Linux kernel, the following vulnerability has been resolved: scsi: pm8001: Fix use-after-free for aborted SSP/STP sas_task Currently a use-after-free may occur if a sas_task is aborted by th…
CVE-2022-48797 unknown In the Linux kernel, the following vulnerability has been resolved: mm: don't try to NUMA-migrate COW pages that have other uses Oded Gabbay reports that enabling NUMA balancing causes corruption w…
CVE-2022-48795 unknown In the Linux kernel, the following vulnerability has been resolved: parisc: Fix data TLB miss in sba_unmap_sg Rolf Eike Beer reported the following bug: [1274934.746891] Bad Address (null pointer …
CVE-2022-48796 unknown In the Linux kernel, the following vulnerability has been resolved: iommu: Fix potential use-after-free during probe Kasan has reported the following use after free on dev->iommu. when a device pro…
CVE-2022-48798 unknown In the Linux kernel, the following vulnerability has been resolved: s390/cio: verify the driver availability for path_event call If no driver is attached to a device or the driver does not provide …
CVE-2022-48799 unknown In the Linux kernel, the following vulnerability has been resolved: perf: Fix list corruption in perf_cgroup_switch() There's list corruption on cgrp_cpuctx_list. This happens on the following path…
CVE-2022-38349 unknown An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving …
CVE-2022-48801 unknown In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Fix file related error handling in IIO_BUFFER_GET_FD_IOCTL If we fail to copy the just created file descriptor to us…
CVE-2022-48802 unknown In the Linux kernel, the following vulnerability has been resolved: fs/proc: task_mmu.c: don't read mapcount for migration entry The syzbot reported the below BUG: kernel BUG at include/linux/pa…
CVE-2022-48805 unknown In the Linux kernel, the following vulnerability has been resolved: net: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup ax88179_rx_fixup() contains several out-of-bounds accesses that ca…
CVE-2022-48808 unknown In the Linux kernel, the following vulnerability has been resolved: net: dsa: fix panic when DSA master device unbinds on shutdown Rafael reports that on a system with LX2160A and Marvell DSA switc…
CVE-2022-31114 unknown 4d ago backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Versions prior to 5.0.13, 4.1.…
CVE-2022-49033 unknown 19d ago Linux kernel vulnerabilities
CVE-2022-49046 unknown 27d ago Linux kernel (BlueField) vulnerabilities
CVE-2022-49635 unknown 1mo ago Linux kernel (Azure) vulnerabilities
CVE-2022-48875 unknown 1mo ago Linux kernel (BlueField) vulnerabilities
CVE-2022-49957 unknown 1y ago In the Linux kernel, the following vulnerability has been resolved: kcm: fix strp_init() order and cleanup strp_init() is called just a few lines above this csk->sk_user_data check, it also initial…
CVE-2022-41137 unknown 2y ago Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore
CVE-2022-23554 unknown 2y ago Alpine allows Authentication Filter bypass
CVE-2022-23553 unknown 2y ago Alpine allows URL access filter bypass
CVE-2022-48833 unknown 2y ago In the Linux kernel, the following vulnerability has been resolved: btrfs: skip reserved bytes warning on unmount after log cleanup failure After the recent changes made by commit c2e39305299f01 ("…
CVE-2022-29946 unknown 2y ago NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one sc…
CVE-2022-30636 unknown 2y ago httpTokenCacheKey uses path.Base to extract the expected HTTP-01 token value to lookup in the DirCache implementation. On Windows, path.Base acts differently to filepath.Base, since Windows uses a di…
CVE-2022-47894 unknown 2y ago Apache Zeppelin SAP: connecting to a malicious SAP server allowed it to perform XXE
CVE-2022-4963 unknown 2y ago SQL injection in Folio Spring Module Core
CVE-2022-34321 unknown 2y ago Apache Pulsar: Improper Authentication for Pulsar Proxy Statistics Endpoint
CVE-2022-45320 unknown 2y ago Privilege escalation in Liferay Portal
CVE-2022-3328 unknown 2y ago Race condition in snap-confine's must_mkdir_and_open_with_perms()
CVE-2022-45135 unknown 3y ago Apache Cocoon SQL Injection vulnerability
CVE-2022-2232 unknown 3y ago Keycloak vulnerable to LDAP Injection on UsernameForm Login
CVE-2022-41678 unknown 3y ago Apache ActiveMQ Deserialization of Untrusted Data vulnerability
CVE-2022-46337 unknown 3y ago Apache Derby: LDAP injection vulnerability in authenticator
CVE-2022-4244 unknown 3y ago plexus-codehaus vulnerable to directory traversal
CVE-2022-4245 unknown 3y ago codehaus-plexus vulnerable to XML injection
CVE-2022-28357 unknown 3y ago NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
CVE-2022-1415 unknown 3y ago Drools Core Deserialization of Untrusted Data vulnerability
CVE-2022-44729 unknown 3y ago Apache XML Graphics Batik Server-Side Request Forgery vulnerability
CVE-2022-46751 unknown 3y ago Apache Ivy External Entity Reference vulnerability
CVE-2022-41401 unknown 3y ago OpenRefine Server-Side Request Forgery vulnerability
CVE-2022-40896 unknown 3y ago A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
CVE-2022-45855 unknown 3y ago Apache Ambari Expression Language Injection vulnerability
CVE-2022-42009 unknown 3y ago Apache Ambari Expression Language Injection vulnerability
CVE-2022-45048 unknown 3y ago Apache Ranger code execution vulnerability in policy expressions
CVE-2022-46365 unknown 3y ago Apache StreamPark Improper Input Validation vulnerability
CVE-2022-45802 unknown 3y ago Apache StreamPark Path Traversal vulnerability
CVE-2022-24697 unknown 3y ago Apache Kylin vulnerable to remote code execution
CVE-2022-4361 unknown 3y ago Keycloak vulnerable to cross-site scripting when validating URI-schemes on SAML and OIDC
CVE-2022-46907 unknown 3y ago Apache JSPWiki vulnerable to cross-site scripting on several plugins
CVE-2022-47937 unknown 3y ago Apache Sling Commons JSON bundle vulnerable to Improper Input Validation
CVE-2022-38784 unknown 3y ago unknown in poppler, poppler-glib, poppler-qt6, poppler-qt5
CVE-2022-45801 unknown 3y ago Apache StreamPark LDAP Injection vulnerability
CVE-2022-45064 unknown 3y ago Apache Sling Engine vulnerable to cross-site scripting (XSS) that can lead to privilege escalation
CVE-2022-41918 unknown 3y ago OpenSearch has issue with fine-grained access control of indices backing data streams
CVE-2022-3277 unknown 3y ago An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates re…
CVE-2022-1274 unknown 3y ago HTML Injection in Keycloak Admin REST API
CVE-2022-4137 unknown 3y ago Keycloak Cross-site Scripting on OpenID connect login service
CVE-2022-1438 unknown 3y ago Keycloak vulnerable to Cross-site Scripting
CVE-2022-39228 unknown 3y ago vantage6 vulnerable to Observable Response Discrepancy
CVE-2022-4492 unknown 3y ago Undertow client not checking server identity presented by server certificate in https connections
CVE-2022-42735 unknown 3y ago Privilege escalation in Apache ShenYu
CVE-2022-4903 unknown 3y ago CodenameOne Pending Intent vulnerability
CVE-2022-24894 unknown 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers…
CVE-2022-24895 unknown 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the…
CVE-2022-44645 unknown 3y ago Apache Linkis contains Deserialization of Untrusted Data
CVE-2022-44644 unknown 3y ago Apache Linkis vulnerable to Exposure of Sensitive Information
CVE-2022-2712 unknown 3y ago Path Traversal In Eclipse GlassFish
CVE-2022-47951 unknown 3y ago An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0…
CVE-2022-25894 unknown 3y ago Remote Code Execution in com.bstek.uflo:uflo-core
CVE-2022-47042 unknown 3y ago Arbitrary file write in net.mingsoft:ms-mcms
CVE-2022-47105 unknown 3y ago Jeecg-boot is vulnerable to SQL injection
CVE-2022-47950 unknown 3y ago An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file c…
CVE-2022-25901 unknown 3y ago cookiejar Regular Expression Denial of Service via Cookie.parse function
CVE-2022-41721 unknown 3y ago A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from th…
CVE-2022-23532 unknown 3y ago org.neo4j.procedure:apoc Path Traversal Vulnerability
CVE-2022-3143 unknown 3y ago Wildfly-elytron possibly vulnerable to timing attacks via use of unsafe comparator
CVE-2022-24913 unknown 3y ago Java Merge-sort Insecure Temporary File vulnerability
CVE-2022-46176 unknown 3y ago Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could explo…
CVE-2022-46769 unknown 4y ago Apache Sling App CMS vulnerable to reflected Cross-site Scripting
CVE-2022-45787 unknown 4y ago Apache James MIME4J vulnerable to information disclosure to local users
CVE-2022-45935 unknown 4y ago Apache James server allows an attacker with local access to access private user data in transit
CVE-2022-45875 unknown 4y ago Apache DolphinScheduler vulnerable to Improper Input Validation
CVE-2022-38723 unknown 4y ago Gravitee API Management contains Path Traversal