2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2663 | MEDIUM | 5.3 | 1.4% | Sep 1, 2022 | An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly ma... |
| CVE-2022-2639 | HIGH | 7.8 | 0.8% | Sep 1, 2022 | An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, whil... |
| CVE-2022-2447 | MEDIUM | 6.6 | 0.6% | Sep 1, 2022 | A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security poli... |
| CVE-2022-2403 | MEDIUM | 6.5 | 0.5% | Sep 1, 2022 | A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate w... |
| CVE-2022-2320 | HIGH | 7.8 | 0.6% | Sep 1, 2022 | A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. ... |
| CVE-2022-2319 | HIGH | 7.8 | 0.4% | Sep 1, 2022 | A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due ... |
| CVE-2022-2308 | MEDIUM | 6.5 | 0.2% | Sep 1, 2022 | A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of ... |
| CVE-2022-2256 | LOW | 3.8 | 0.5% | Sep 1, 2022 | A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This fla... |
| CVE-2022-2238 | MEDIUM | 6.5 | 0.8% | Sep 1, 2022 | A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query... |
| CVE-2022-23452 | MEDIUM | 4.9 | 1.0% | Sep 1, 2022 | An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different ... |
| CVE-2022-1902 | HIGH | 8.8 | 1.1% | Sep 1, 2022 | A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized i... |
| CVE-2022-1729 | HIGH | 7 | 0.3% | Sep 1, 2022 | A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain ... |
| CVE-2022-1677 | MEDIUM | 6.3 | 0.5% | Sep 1, 2022 | In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a m... |
| CVE-2022-1632 | MEDIUM | 6.5 | 0.3% | Sep 1, 2022 | An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate expli... |
| CVE-2022-1615 | MEDIUM | 5.5 | 0.4% | Sep 1, 2022 | In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values. |
| CVE-2022-36773 | HIGH | 8.1 | 1.4% | Sep 1, 2022 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when proc... |
| CVE-2022-34380 | HIGH | 8.2 | 0.2% | Sep 1, 2022 | Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulner... |
| CVE-2022-34379 | CRITICAL | 9.8 | 0.9% | Sep 1, 2022 | Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with ... |
| CVE-2022-34372 | CRITICAL | 9.1 | 1.0% | Sep 1, 2022 | Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unau... |
| CVE-2022-30614 | HIGH | 7.5 | 1.3% | Sep 1, 2022 | IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sendin... |
| CVE-2022-3061 | MEDIUM | 5.5 | 0.3% | Sep 1, 2022 | Found Linux Kernel flaw in the i740 driver. The Userspace program could pass any values to the driver through ioctl() in... |
| CVE-2022-36583 | MEDIUM | 6.1 | 0.5% | Sep 1, 2022 | DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the... |
| CVE-2022-2996 | HIGH | 7.4 | 0.5% | Sep 1, 2022 | A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate wou... |
| CVE-2022-36796 | MEDIUM | 6.1 | 0.3% | Sep 1, 2022 | Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in CallRail, Inc. CallRail ... |
| CVE-2022-36373 | HIGH | 8.8 | 0.4% | Sep 1, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Simon Ward MP3 jPlayer plugin <= 2.7.3 at WordPress. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now