2022 CVE Vulnerabilities

27,528 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-22991HIGH8.8A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device int...
CVE-2022-22990HIGH8.8A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code executi...
CVE-2022-21684HIGH8.8Discourse is an open source discussion platform. Versions prior to 2.7.13 in `stable`, 2.8.0.beta11 in `beta`, and 2.8.0...
CVE-2022-23132HIGH7.3During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] ...
CVE-2022-22113HIGH8.8In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a passwor...
CVE-2022-0198HIGH7.1corenlp is vulnerable to Improper Restriction of XML External Entity Reference
CVE-2022-0197HIGH8.8phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2022-0196HIGH8.8phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2022-23118HIGH8.8Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-l...
CVE-2022-23117HIGH7.5Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent pro...
CVE-2022-23116HIGH7.5Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent pro...
CVE-2022-23107HIGH8.1Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ...
CVE-2022-20619HIGH7.1A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlie...
CVE-2022-20617HIGH8.8Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS comma...
CVE-2022-21676HIGH7.5Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Soc...
CVE-2022-21675HIGH7.8Bytecode Viewer (BCV) is a Java/Android reverse engineering suite. Versions of the package prior to 2.11.0 are vulnerabl...
CVE-2022-0015HIGH7.8A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authen...
CVE-2022-0014HIGH7.3An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker w...
CVE-2022-0012HIGH7.1An improper link resolution before file access vulnerability exists in the Palo Alto Networks Cortex XDR agent on Window...
CVE-2022-21646HIGH8.1SpiceDB is a database system for managing security-critical application permissions. Any user making use of a wildcard r...
CVE-2022-21922HIGH8.8Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVE-2022-21920HIGH8.8Windows Kerberos Elevation of Privilege Vulnerability
CVE-2022-21919HIGH7Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2022-21917HIGH7.8HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2022-21916HIGH7.8Windows Common Log File System Driver Elevation of Privilege Vulnerability

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now