2022 CVE Vulnerabilities
27,528 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43565 | HIGH | 8.8 | 0.6% | Nov 4, 2022 | In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the ‘tstats command handles Javascript Object Notatio... |
| CVE-2022-43564 | MEDIUM | 6.5 | 0.8% | Nov 4, 2022 | In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, a remote user who can create search macros and schedule se... |
| CVE-2022-43563 | HIGH | 8.8 | 0.6% | Nov 4, 2022 | In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an at... |
| CVE-2022-43562 | MEDIUM | 5.4 | 0.4% | Nov 4, 2022 | In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, Splunk Enterprise fails to properly validate and escape th... |
| CVE-2022-39384 | MEDIUM | 5.6 | 0.5% | Nov 4, 2022 | OpenZeppelin Contracts is a library for secure smart contract development. Before version 4.4.1 but after 3.2.0, initial... |
| CVE-2022-38654 | MEDIUM | 5.5 | 0.2% | Nov 4, 2022 | HCL Domino is susceptible to an information disclosure vulnerability. In some scenarios, local calls made on the server... |
| CVE-2022-39344 | CRITICAL | 9.8 | 1.9% | Nov 4, 2022 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS Thre... |
| CVE-2022-38660 | HIGH | 8.8 | 0.3% | Nov 4, 2022 | HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attack... |
| CVE-2022-43945 | HIGH | 7.5 | 21.3% | Nov 4, 2022 | The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks ... |
| CVE-2022-40263 | HIGH | 7.8 | 0.2% | Nov 4, 2022 | BD Totalys MultiProcessor, versions 1.70 and earlier, contain hardcoded credentials. If exploited, threat actors may be ... |
| CVE-2022-39387 | HIGH | 7.5 | 0.9% | Nov 4, 2022 | XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Prior to version 1.29.1, even if a wiki has... |
| CVE-2022-31691 | CRITICAL | 9.8 | 2.4% | Nov 4, 2022 | Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI... |
| CVE-2022-27894 | MEDIUM | 5.4 | 0.3% | Nov 4, 2022 | The Foundry Blobster service was found to have a cross-site scripting (XSS) vulnerability that could have allowed an att... |
| CVE-2022-20969 | MEDIUM | 5.4 | 0.4% | Nov 4, 2022 | A vulnerability in multiple management dashboard pages of Cisco Umbrella could allow an authenticated, remote attacker t... |
| CVE-2022-20963 | MEDIUM | 5.4 | 0.4% | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2022-20962 | HIGH | 8.8 | 1.0% | Nov 4, 2022 | A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated... |
| CVE-2022-20961 | HIGH | 8.8 | 0.4% | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthentic... |
| CVE-2022-20960 | HIGH | 7.5 | 0.8% | Nov 4, 2022 | A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote... |
| CVE-2022-20958 | HIGH | 8.8 | 0.9% | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthent... |
| CVE-2022-20956 | HIGH | 8.8 | 1.3% | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2022-20951 | MEDIUM | 6.5 | 1.9% | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an authentic... |
| CVE-2022-20942 | MEDIUM | 6.5 | 0.9% | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and We... |
| CVE-2022-20937 | MEDIUM | 5.3 | 0.8% | Nov 4, 2022 | A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow ... |
| CVE-2022-20868 | HIGH | 8.8 | 0.7% | Nov 4, 2022 | A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Mana... |
| CVE-2022-20867 | MEDIUM | 6.5 | 0.8% | Nov 4, 2022 | A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and We... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now