CVEs from 2022

5,250 normalized CVEs published or assigned in this year.

Total
5,250
critical
critical 90
high
high 1,231
medium
medium 959
low
low 24
% Critical
1.7%
% with KEV
2.5%
% with exploit
3.4%

Top products

  • jdk 116
  • jre 109
  • openjdk 100
  • zulu 82
  • graalvm 74
  • cloud_secure_agent 35
  • oncommand_insight 34
  • cloud_insights_acquisition_unit 34
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-2309 medium 5.5 4y ago NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earli…
CVE-2022-49347 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix bug_on in ext4_writepages we got issue as follows: EXT4-fs error (device loop0): ext4_mb_generate_buddy:1141: group 0, …
CVE-2022-3500 medium 5.5 4y ago Moderate: keylime security update
CVE-2022-49561 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: re-fetch conntrack after insertion In case the conntrack is clashing, insertion can free skb->_nfct and set…
CVE-2022-49325 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: tcp: add accessors to read/set tp->snd_cwnd We had various bugs over the years with code breaking the assumption that tp->snd_cwn…
CVE-2022-49584 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: ixgbe: Add locking to prevent panic when setting sriov_numvfs to zero It is possible to disable VFs while the PF driver is proces…
CVE-2022-32816 medium 5.5 4y ago The issue was addressed with improved UI handling. This issue is fixed in watchOS 8.7, tvOS 15.6, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. Visiting a website that frames malicious content may l…
CVE-2022-32792 medium 5.5 4y ago An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing malici…
CVE-2022-30293 medium 5.5 4y ago In WebKitGTK through 2.36.0 (and WPE WebKit), there is a heap-based buffer overflow in WebCore::TextureMapperLayer::setContentsLayer in WebCore/platform/graphics/texmap/TextureMapperLayer.cpp.
CVE-2022-26719 medium 5.5 4y ago A memory corruption issue was addressed with improved state management. This issue is fixed in tvOS 15.5, iOS 15.5 and iPadOS 15.5, watchOS 8.6, macOS Monterey 12.4, Safari 15.5. Processing malicious…
CVE-2022-26717 medium 5.5 4y ago A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.5, watchOS 8.6, iOS 15.5 and iPadOS 15.5, macOS Monterey 12.4, Safari 15.5, iTunes 12.12.4 for Win…
CVE-2022-32746 medium 5.5 4y ago RHSA-2022:7730: libldb security, bug fix, and enhancement update (Moderate)
CVE-2022-49605 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: igc: Reinstate IGC_REMOVED logic and implement it properly The initially merged version of the igc driver code (via commit 146740…
CVE-2022-49228 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a btf decl_tag bug when tagging a function syzbot reported a btf decl_tag bug with stack trace below: general protect…
CVE-2022-41105 medium 5.5 5.5 4y ago Microsoft Excel Information Disclosure Vulnerability
CVE-2022-41104 medium 5.5 5.5 4y ago Microsoft Excel Security Feature Bypass Vulnerability
CVE-2022-41103 medium 5.5 5.5 4y ago Microsoft Word Information Disclosure Vulnerability
CVE-2022-41060 medium 5.5 5.5 4y ago Microsoft Word Information Disclosure Vulnerability
CVE-2022-21682 medium 5.5 4y ago RHSA-2022:7458: flatpak-builder security and bug fix update (Moderate)
CVE-2022-23960 medium 5.5 4y ago Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buf…
CVE-2022-27950 medium 5.5 4y ago In drivers/hid/hid-elo.c in the Linux kernel before 5.16.11, a memory leak exists for a certain hid_parse error condition.
CVE-2022-21824 medium 5.5 4y ago RHSA-2022:9073: nodejs:16 security, bug fix, and enhancement update (Moderate)
CVE-2022-2938 medium 5.5 4y ago A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corr…
CVE-2022-49616 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: ASoC: rt7*-sdw: harden jack_detect_handler Realtek headset codec drivers typically check if the card is instantiated before proce…
CVE-2022-49674 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: dm raid: fix accesses beyond end of raid member array On dm-raid table load (using raid_ctr), dm-raid allocates an array rs->devs…
CVE-2022-33099 medium 5.5 4y ago Moderate: lua security update
CVE-2022-37434 medium 5.5 4y ago Moderate: rsync security and bug fix update
CVE-2022-50095 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Cleanup CPU timers before freeing them during exec Commit 55e8c8eb2c7b ("posix-cpu-timers: Store a reference to…
CVE-2022-49281 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: cifs: fix handlecache and multiuser In multiuser each individual user has their own tcon structure for the share and thus their o…
CVE-2022-21378 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21352 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21256 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21600 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21370 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-49611 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: x86/speculation: Fill RSB on vmexit for IBRS Prevent RSB underflow/poisoning attacks with RSB. While at it, add a bunch of comme…
CVE-2022-21270 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21348 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21254 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21265 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21301 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21302 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21344 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21264 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21278 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21339 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21303 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21342 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-49610 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Prevent RSB underflow before vmenter On VMX, there are some balanced returns between the time the guest's SPEC_CTRL val…
CVE-2022-21253 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21304 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21362 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21249 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21297 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21374 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21245 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21372 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21379 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21368 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21351 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21367 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21358 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21628 medium 5.5 4y ago RHSA-2023:0128: java-1.8.0-ibm security update (Moderate)
CVE-2022-33068 medium 5.5 4y ago RHSA-2022:7012: java-11-openjdk security and bug fix update (Moderate)
CVE-2022-41032 medium 5.5 4y ago RHSA-2022:7826: dotnet7.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-2509 medium 5.5 4y ago Moderate: gnutls and nettle security, bug fix, and enhancement update
CVE-2022-3102 medium 5.5 4y ago jwcrypto token substitution can lead to authentication bypass
CVE-2022-32214 medium 5.5 4y ago The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).
CVE-2022-21635 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21538 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21534 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21451 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21529 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21528 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21462 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-29244 medium 5.5 4y ago Moderate: nodejs and nodejs-nodemon security and bug fix update
CVE-2022-21413 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-33987 medium 5.5 4y ago RHSA-2022:6449: nodejs:16 security and bug fix update (Moderate)
CVE-2022-32215 medium 5.5 4y ago The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
CVE-2022-31212 medium 5.5 4y ago Moderate: dbus-broker security update
CVE-2022-21425 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21454 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21457 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21459 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-28739 medium 5.5 4y ago Moderate: ruby security, bug fix, and enhancement update
CVE-2022-49063 medium 5.5 4y ago In the Linux kernel, the following vulnerability has been resolved: ice: arfs: fix use-after-free when freeing @rx_cpu_rmap The CI testing bots triggered the following splat: [ 718.203054] BUG: K…
CVE-2022-28738 medium 5.5 4y ago Moderate: ruby security, bug fix, and enhancement update
CVE-2022-2078 medium 5.5 4y ago A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to trigger a buffer overflow via nft_set_desc_concat_parse() , causing a denial of s…
CVE-2022-21415 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21539 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21479 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21553 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21525 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21530 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21569 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21455 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21517 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21537 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21460 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21444 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)
CVE-2022-21418 medium 5.5 4y ago RHSA-2022:7119: mysql:8.0 security, bug fix, and enhancement update (Moderate)