2022 CVE Vulnerabilities
27,528 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22991 | HIGH | 8.8 | 1.3% | Jan 13, 2022 | A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device int... |
| CVE-2022-22990 | HIGH | 8.8 | 2.1% | Jan 13, 2022 | A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code executi... |
| CVE-2022-21684 | HIGH | 8.8 | 1.0% | Jan 13, 2022 | Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0... |
| CVE-2022-23132 | HIGH | 7.3 | 0.8% | Jan 13, 2022 | During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] ... |
| CVE-2022-22113 | HIGH | 8.8 | 1.0% | Jan 13, 2022 | In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a passwor... |
| CVE-2022-0198 | HIGH | 7.1 | 0.7% | Jan 13, 2022 | corenlp is vulnerable to Improper Restriction of XML External Entity Reference |
| CVE-2022-0197 | HIGH | 8.8 | 0.8% | Jan 13, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2022-0196 | HIGH | 8.8 | 0.7% | Jan 13, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2022-23118 | HIGH | 8.8 | 1.6% | Jan 12, 2022 | Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-l... |
| CVE-2022-23117 | HIGH | 7.5 | 1.3% | Jan 12, 2022 | Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent pro... |
| CVE-2022-23116 | HIGH | 7.5 | 0.8% | Jan 12, 2022 | Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent pro... |
| CVE-2022-23107 | HIGH | 8.1 | 1.9% | Jan 12, 2022 | Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ... |
| CVE-2022-20619 | HIGH | 7.1 | 0.7% | Jan 12, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlie... |
| CVE-2022-20617 | HIGH | 8.8 | 2.3% | Jan 12, 2022 | Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS comma... |
| CVE-2022-21676 | HIGH | 7.5 | 2.8% | Jan 12, 2022 | Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Soc... |
| CVE-2022-21675 | HIGH | 7.8 | 2.5% | Jan 12, 2022 | Bytecode Viewer (BCV) is a Java/Android reverse engineering suite. Versions of the package prior to 2.11.0 are vulnerabl... |
| CVE-2022-0015 | HIGH | 7.8 | 0.2% | Jan 12, 2022 | A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authen... |
| CVE-2022-0014 | HIGH | 7.3 | 0.3% | Jan 12, 2022 | An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker w... |
| CVE-2022-0012 | HIGH | 7.1 | 0.2% | Jan 12, 2022 | An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Window... |
| CVE-2022-21646 | HIGH | 8.1 | 1.5% | Jan 11, 2022 | SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard r... |
| CVE-2022-21922 | HIGH | 8.8 | 2.8% | Jan 11, 2022 | Remote Procedure Call Runtime Remote Code Execution Vulnerability |
| CVE-2022-21920 | HIGH | 8.8 | 2.8% | Jan 11, 2022 | Windows Kerberos Elevation of Privilege Vulnerability |
| CVE-2022-21919 | HIGH | 7 | 2.9% | Jan 11, 2022 | Windows User Profile Service Elevation of Privilege Vulnerability |
| CVE-2022-21917 | HIGH | 7.8 | 3.6% | Jan 11, 2022 | HEVC Video Extensions Remote Code Execution Vulnerability |
| CVE-2022-21916 | HIGH | 7.8 | 1.0% | Jan 11, 2022 | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now