CVEs from 2022

5,244 normalized CVEs published or assigned in this year.

Total
5,244
critical
critical 92
high
high 1,233
medium
medium 961
low
low 24
% Critical
1.8%
% with KEV
2.5%
% with exploit
3.4%

Top products

  • jdk 116
  • jre 109
  • openjdk 100
  • zulu 82
  • graalvm 74
  • cloud_secure_agent 35
  • oncommand_insight 34
  • cloud_insights_acquisition_unit 34
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-49625 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: sfc: fix kernel panic when creating VF When creating VFs a kernel panic can happen when calling to efx_ef10_try_update_nic_stats_…
CVE-2022-49664 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: tipc: move bc link creation back to tipc_node_create Shuang Li reported a NULL pointer dereference crash: [] BUG: kernel NULL …
CVE-2022-49669 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race on unaccepted mptcp sockets When the listener socket owning the relevant request is closed, it frees the unaccept…
CVE-2022-49671 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: RDMA/cm: Fix memory leak in ib_cm_insert_listen cm_alloc_id_priv() allocates resource for the cm_id_priv. When cm_init_listen() f…
CVE-2022-49673 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: dm raid: fix KASAN warning in raid5_add_disks There's a KASAN warning in raid5_add_disk when running the LVM testsuite. The warni…
CVE-2022-49695 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: igb: fix a use-after-free issue in igb_clean_tx_ring Fix the following use-after-free bug in igb_clean_tx_ring routine when the N…
CVE-2022-49697 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: bpf: Fix request_sock leak in sk lookup helpers A customer reported a request_socket leak in a Calico cloud environment. We found…
CVE-2022-49698 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: netfilter: use get_random_u32 instead of prandom bh might occur while updating per-cpu rnd_state from user context, ie. local_out…
CVE-2022-49708 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug_on ext4_mb_use_inode_pa Hulk Robot reported a BUG_ON: =============================================================…
CVE-2022-50030 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Prevent buffer overflow crashes in debugfs with malformed user input Malformed user input to debugfs results in buffe…
CVE-2022-50084 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: dm raid: fix address sanitizer warning in raid_status There is this warning when using a kernel with the address sanitizer and ru…
CVE-2022-50085 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: dm raid: fix address sanitizer warning in raid_resume There is a KASAN warning in raid_resume when running the lvm test lvconvert…
CVE-2022-50092 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: dm thin: fix use-after-free crash in dm_sm_register_threshold_callback Fault inject on pool metadata device reports: BUG: KASAN…
CVE-2022-50212 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: do not allow CHAIN_ID to refer to another table When doing lookups for chains on the same batch by using it…
CVE-2022-27337 medium 5.5 4y ago A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
CVE-2022-49228 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a btf decl_tag bug when tagging a function syzbot reported a btf decl_tag bug with stack trace below: general protect…
CVE-2022-49605 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: igc: Reinstate IGC_REMOVED logic and implement it properly The initially merged version of the igc driver code (via commit 146740…
CVE-2022-41105 medium 5.5 5.5 4y ago Microsoft Excel Information Disclosure Vulnerability
CVE-2022-41104 medium 5.5 5.5 4y ago Microsoft Excel Security Feature Bypass Vulnerability
CVE-2022-41103 medium 5.5 5.5 4y ago Microsoft Word Information Disclosure Vulnerability
CVE-2022-41060 medium 5.5 5.5 4y ago Microsoft Word Information Disclosure Vulnerability
CVE-2022-21824 medium 5.5 4y ago RHSA-2022:9073: nodejs:16 security, bug fix, and enhancement update (Moderate)
CVE-2022-2938 medium 5.5 4y ago A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corr…
CVE-2022-49616 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: ASoC: rt7*-sdw: harden jack_detect_handler Realtek headset codec drivers typically check if the card is instantiated before proce…
CVE-2022-49674 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: dm raid: fix accesses beyond end of raid member array On dm-raid table load (using raid_ctr), dm-raid allocates an array rs->devs…
CVE-2022-23960 medium 5.5 4y ago Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buf…
CVE-2022-27950 medium 5.5 4y ago In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error condition.
CVE-2022-21682 medium 5.5 4y ago RHSA-2022:7458: flatpak-builder security and bug fix update (Moderate)
CVE-2022-49281 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: cifs: fix handlecache and multiuser In multiuser each individual user has their own tcon structure for the share and thus their o…
CVE-2022-33099 medium 5.5 4y ago Moderate: lua security update
CVE-2022-50095 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Cleanup CPU timers before freeing them during exec Commit 55e8c8eb2c7b ("posix-cpu-timers: Store a reference to…
CVE-2022-37434 medium 5.5 4y ago Moderate: rsync security and bug fix update
CVE-2022-21297 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-49610 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Prevent RSB underflow before vmenter On VMX, there are some balanced returns between the time the guest's SPEC_CTRL val…
CVE-2022-21600 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21378 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-49611 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: x86/speculation: Fill RSB on vmexit for IBRS Prevent RSB underflow/poisoning attacks with RSB. While at it, add a bunch of comme…
CVE-2022-21368 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21362 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21372 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21358 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21367 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21342 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21351 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21304 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21303 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21370 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21256 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21339 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21348 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21302 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21278 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21264 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21265 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21270 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21253 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21379 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21249 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21245 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21301 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21344 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21352 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21374 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21254 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21628 medium 5.5 4y ago RHSA-2023:0128: java-1.8.0-ibm security update (Moderate)
CVE-2022-33068 medium 5.5 4y ago RHSA-2022:7012: java-11-openjdk security and bug fix update (Moderate)
CVE-2022-41032 medium 5.5 4y ago RHSA-2022:7826: dotnet7.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-2509 medium 5.5 4y ago Moderate: gnutls and nettle security, bug fix, and enhancement update
CVE-2022-3102 medium 5.5 4y ago jwcrypto token substitution can lead to authentication bypass
CVE-2022-34903 medium 5.5 4y ago RHSA-2022:6463: gnupg2 security update (Moderate)
CVE-2022-21457 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21452 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-2553 medium 5.5 4y ago Moderate: booth security update
CVE-2022-49722 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: ice: Fix memory corruption in VF driver Disable VF's RX/TX queues, when it's disabled. VF can have queues enabled, when it reques…
CVE-2022-32212 medium 5.5 4y ago RHSA-2022:6449: nodejs:16 security and bug fix update (Moderate)
CVE-2022-21525 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21462 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21418 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21414 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21641 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-31212 medium 5.5 4y ago Moderate: dbus-broker security update
CVE-2022-21635 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21413 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21527 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-32213 medium 5.5 4y ago The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
CVE-2022-2078 medium 5.5 4y ago A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to trigger a buffer overflow via nft_set_desc_concat_parse() , causing a denial of s…
CVE-2022-29244 medium 5.5 4y ago Moderate: nodejs and nodejs-nodemon security and bug fix update
CVE-2022-33987 medium 5.5 4y ago RHSA-2022:6449: nodejs:16 security and bug fix update (Moderate)
CVE-2022-31213 medium 5.5 4y ago Moderate: dbus-broker security update
CVE-2022-21592 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21638 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21440 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-28739 medium 5.5 4y ago Moderate: ruby security, bug fix, and enhancement update
CVE-2022-28738 medium 5.5 4y ago Moderate: ruby security, bug fix, and enhancement update
CVE-2022-21509 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21425 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21437 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21459 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21478 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21605 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)