2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3740 | MEDIUM | 4.9 | 0.9% | Jan 26, 2023 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15... |
| CVE-2022-3736 | HIGH | 7.5 | 50.2% | Jan 26, 2023 | BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to... |
| CVE-2022-3572 | MEDIUM | 6.1 | 1.1% | Jan 26, 2023 | A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 ... |
| CVE-2022-3488 | HIGH | 7.5 | 19.0% | Jan 26, 2023 | Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first... |
| CVE-2022-3482 | MEDIUM | 5.3 | 1.0% | Jan 26, 2023 | An improper access control issue in GitLab CE/EE affecting all versions from 11.3 prior to 15.3.5, 15.4 prior to 15.4.4,... |
| CVE-2022-3478 | MEDIUM | 4.3 | 1.0% | Jan 26, 2023 | An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.4.6, all versions starting fr... |
| CVE-2022-3432 | MEDIUM | 6.7 | 0.3% | Jan 26, 2023 | A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly no... |
| CVE-2022-3094 | HIGH | 7.5 | 13.1% | Jan 26, 2023 | Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `... |
| CVE-2022-38775 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged... |
| CVE-2022-38774 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which co... |
| CVE-2022-38758 | MEDIUM | 6.1 | 0.4% | Jan 26, 2023 | Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious s... |
| CVE-2022-34405 | HIGH | 7.3 | 0.3% | Jan 26, 2023 | An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious use... |
| CVE-2022-31711 | MEDIUM | 5.3 | 21.7% | Jan 26, 2023 | VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sen... |
| CVE-2022-31710 | HIGH | 7.5 | 1.5% | Jan 26, 2023 | vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger t... |
| CVE-2022-31706 | CRITICAL | 9.8 | 87.1% | Jan 26, 2023 | The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject fi... |
| CVE-2022-31704 | CRITICAL | 9.8 | 81.0% | Jan 26, 2023 | The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely... |
| CVE-2022-29844 | CRITICAL | 9.8 | 36.4% | Jan 26, 2023 | A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119 ... |
| CVE-2022-29843 | CRITICAL | 9.8 | 1.2% | Jan 26, 2023 | A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running fir... |
| CVE-2022-27508 | HIGH | 7.5 | 1.0% | Jan 26, 2023 | Unauthenticated denial of service |
| CVE-2022-27507 | MEDIUM | 6.5 | 1.0% | Jan 26, 2023 | Authenticated denial of service |
| CVE-2022-26329 | MEDIUM | 5.3 | 0.5% | Jan 26, 2023 | File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to deter... |
| CVE-2022-25962 | CRITICAL | 9.8 | 1.0% | Jan 26, 2023 | All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input... |
| CVE-2022-25927 | HIGH | 7.5 | 1.7% | Jan 26, 2023 | Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regul... |
| CVE-2022-25908 | CRITICAL | 9.8 | 1.5% | Jan 26, 2023 | All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to... |
| CVE-2022-25894 | CRITICAL | 9.8 | 2.6% | Jan 26, 2023 | All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionCont... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now