2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2251 | HIGH | 8 | 1.2% | Jan 17, 2023 | Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and... |
| CVE-2022-23538 | HIGH | 7.6 | 0.7% | Jan 17, 2023 | github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Ser... |
| CVE-2022-4891 | HIGH | 7.5 | 1.3% | Jan 17, 2023 | A vulnerability has been found in Sisimai up to 4.25.14p11 and classified as problematic. This vulnerability affects the... |
| CVE-2022-37436 | MEDIUM | 5.3 | 57.9% | Jan 17, 2023 | Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting ... |
| CVE-2022-36760 | CRITICAL | 9 | 1.9% | Jan 17, 2023 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Se... |
| CVE-2022-47853 | CRITICAL | 9.8 | 1.9% | Jan 17, 2023 | TOTOlink A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection Vulnerability in the httpd service. An attacke... |
| CVE-2022-40704 | MEDIUM | 6.1 | 0.6% | Jan 17, 2023 | A XSS vulnerability was found in phoromatic_r_add_test_details.php in phoronix-test-suite. |
| CVE-2022-3650 | HIGH | 7.8 | 0.3% | Jan 17, 2023 | A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root... |
| CVE-2022-23739 | CRITICAL | 9.8 | 1.2% | Jan 17, 2023 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileg... |
| CVE-2022-4121 | MEDIUM | 5.5 | 0.5% | Jan 17, 2023 | In libetpan a null pointer dereference in mailimap_mailbox_data_status_free in low-level/imap/mailimap_types.c was found... |
| CVE-2022-41861 | MEDIUM | 6.5 | 1.1% | Jan 17, 2023 | A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which ca... |
| CVE-2022-41860 | HIGH | 7.5 | 1.2% | Jan 17, 2023 | In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the... |
| CVE-2022-41859 | HIGH | 7.5 | 0.9% | Jan 17, 2023 | In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an atta... |
| CVE-2022-41858 | HIGH | 7.1 | 0.3% | Jan 17, 2023 | A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach ... |
| CVE-2022-4621 | HIGH | 8.8 | 0.3% | Jan 17, 2023 | Panasonic Sanyo CCTV Network Cameras versions 1.02-05 and 2.03-0x are vulnerable to CSRFs that can be exploited to allo... |
| CVE-2022-3091 | HIGH | 7.5 | 0.6% | Jan 17, 2023 | RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials.... |
| CVE-2022-2893 | MEDIUM | 6.5 | 0.7% | Jan 17, 2023 | RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to s... |
| CVE-2022-47318 | HIGH | 8 | 1.4% | Jan 17, 2023 | ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a ... |
| CVE-2022-46648 | HIGH | 8 | 1.4% | Jan 17, 2023 | ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a ... |
| CVE-2022-46891 | HIGH | 8.8 | 0.8% | Jan 17, 2023 | An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make imp... |
| CVE-2022-40273 | — | — | — | Jan 17, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2022-40272 | — | — | — | Jan 17, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2022-40271 | — | — | — | Jan 17, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2022-40270 | — | — | — | Jan 17, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
| CVE-2022-3117 | — | — | — | Jan 17, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now