2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3740MEDIUM4.9An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15...
CVE-2022-3736HIGH7.5BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to...
CVE-2022-3572MEDIUM6.1A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 ...
CVE-2022-3488HIGH7.5Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first...
CVE-2022-3482MEDIUM5.3An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4,...
CVE-2022-3478MEDIUM4.3An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting fr...
CVE-2022-3432MEDIUM6.7A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly no...
CVE-2022-3094HIGH7.5Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `...
CVE-2022-38775HIGH7.8An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged...
CVE-2022-38774HIGH7.8An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which co...
CVE-2022-38758MEDIUM6.1Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious s...
CVE-2022-34405HIGH7.3An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious use...
CVE-2022-31711MEDIUM5.3VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sen...
CVE-2022-31710HIGH7.5vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger t...
CVE-2022-31706CRITICAL9.8The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject fi...
CVE-2022-31704CRITICAL9.8The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely...
CVE-2022-29844CRITICAL9.8A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 ...
CVE-2022-29843CRITICAL9.8A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running fir...
CVE-2022-27508HIGH7.5Unauthenticated denial of service
CVE-2022-27507MEDIUM6.5Authenticated denial of service
CVE-2022-26329MEDIUM5.3File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to deter...
CVE-2022-25962CRITICAL9.8All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input...
CVE-2022-25927HIGH7.5Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regul...
CVE-2022-25908CRITICAL9.8All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to...
CVE-2022-25894CRITICAL9.8All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionCont...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now