2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-41833HIGH7.5In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, und...
CVE-2022-41832HIGH7.5In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 1...
CVE-2022-41806HIGH7.5In versions 16.1.x before 16.1.3.2 and 15.1.x before 15.1.5.1, when BIG-IP AFM Network Address Translation policy with I...
CVE-2022-41787HIGH7.5In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 1...
CVE-2022-41743HIGH7NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module that might allow a l...
CVE-2022-41742HIGH7.1NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and...
CVE-2022-41741HIGH7.8NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and...
CVE-2022-41691HIGH7.5When a BIG-IP Advanced WAF/ASM security policy is configured on a virtual server, undisclosed requests can cause the bd ...
CVE-2022-41624HIGH7.5In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.2, 15.1.x before 15.1.7, 14.1.x before 14.1.5.2, and 13....
CVE-2022-41617HIGH7.2In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the...
CVE-2022-36795HIGH7.5In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, and 14.1.x before 14.1.5.1, whe...
CVE-2022-42227HIGH7.5jsonlint 1.0 is vulnerable to heap-buffer-overflow via /home/hjsz/jsonlint/src/lexer.
CVE-2022-23241HIGH8.1Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerabi...
CVE-2022-1738HIGH7.5Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to an out-of-bounds read, which could allow an attacker to...
CVE-2022-1414HIGH8.83scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user co...
CVE-2022-41709HIGH7.8Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to vie...
CVE-2022-43430HIGH7.5Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML externa...
CVE-2022-43429HIGH7.5Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not lim...
CVE-2022-43416HIGH8.8Jenkins Katalon Plugin 1.0.32 and earlier implements an agent/controller message that does not limit where it can be exe...
CVE-2022-43415HIGH7.5Jenkins REPO Plugin 1.15.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-43407HIGH8.8Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specifi...
CVE-2022-43042HIGH7.8GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function FixSDTPInTRAF at...
CVE-2022-43040HIGH7.8GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function gf_isom_box_dump...
CVE-2022-23734HIGH8.8A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that could potentially lead...
CVE-2022-3608HIGH8.4Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.0-alpha.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now