2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41833 | HIGH | 7.5 | 0.6% | Oct 19, 2022 | In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, und... |
| CVE-2022-41832 | HIGH | 7.5 | 0.6% | Oct 19, 2022 | In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 1... |
| CVE-2022-41806 | HIGH | 7.5 | 0.6% | Oct 19, 2022 | In versions 16.1.x before 16.1.3.2 and 15.1.x before 15.1.5.1, when BIG-IP AFM Network Address Translation policy with I... |
| CVE-2022-41787 | HIGH | 7.5 | 0.6% | Oct 19, 2022 | In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 1... |
| CVE-2022-41743 | HIGH | 7 | 0.2% | Oct 19, 2022 | NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module that might allow a l... |
| CVE-2022-41742 | HIGH | 7.1 | 1.1% | Oct 19, 2022 | NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and... |
| CVE-2022-41741 | HIGH | 7.8 | 0.8% | Oct 19, 2022 | NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and... |
| CVE-2022-41691 | HIGH | 7.5 | 0.6% | Oct 19, 2022 | When a BIG-IP Advanced WAF/ASM security policy is configured on a virtual server, undisclosed requests can cause the bd ... |
| CVE-2022-41624 | HIGH | 7.5 | 0.6% | Oct 19, 2022 | In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.2, 15.1.x before 15.1.7, 14.1.x before 14.1.5.2, and 13.... |
| CVE-2022-41617 | HIGH | 7.2 | 1.1% | Oct 19, 2022 | In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the... |
| CVE-2022-36795 | HIGH | 7.5 | 0.6% | Oct 19, 2022 | In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, and 14.1.x before 14.1.5.1, whe... |
| CVE-2022-42227 | HIGH | 7.5 | 0.9% | Oct 19, 2022 | jsonlint 1.0 is vulnerable to heap-buffer-overflow via /home/hjsz/jsonlint/src/lexer. |
| CVE-2022-23241 | HIGH | 8.1 | 0.7% | Oct 19, 2022 | Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerabi... |
| CVE-2022-1738 | HIGH | 7.5 | 0.5% | Oct 19, 2022 | Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to an out-of-bounds read, which could allow an attacker to... |
| CVE-2022-1414 | HIGH | 8.8 | 0.8% | Oct 19, 2022 | 3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user co... |
| CVE-2022-41709 | HIGH | 7.8 | 0.4% | Oct 19, 2022 | Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to vie... |
| CVE-2022-43430 | HIGH | 7.5 | 0.7% | Oct 19, 2022 | Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML externa... |
| CVE-2022-43429 | HIGH | 7.5 | 0.6% | Oct 19, 2022 | Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not lim... |
| CVE-2022-43416 | HIGH | 8.8 | 1.1% | Oct 19, 2022 | Jenkins Katalon Plugin 1.0.32 and earlier implements an agent/controller message that does not limit where it can be exe... |
| CVE-2022-43415 | HIGH | 7.5 | 0.9% | Oct 19, 2022 | Jenkins REPO Plugin 1.15.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2022-43407 | HIGH | 8.8 | 0.5% | Oct 19, 2022 | Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specifi... |
| CVE-2022-43042 | HIGH | 7.8 | 0.3% | Oct 19, 2022 | GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function FixSDTPInTRAF at... |
| CVE-2022-43040 | HIGH | 7.8 | 0.3% | Oct 19, 2022 | GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function gf_isom_box_dump... |
| CVE-2022-23734 | HIGH | 8.8 | 1.9% | Oct 19, 2022 | A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that could potentially lead... |
| CVE-2022-3608 | HIGH | 8.4 | 0.9% | Oct 19, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-alpha. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now