2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2663MEDIUM5.3An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly ma...
CVE-2022-2639HIGH7.8An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, whil...
CVE-2022-2447MEDIUM6.6A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security poli...
CVE-2022-2403MEDIUM6.5A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate w...
CVE-2022-2320HIGH7.8A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. ...
CVE-2022-2319HIGH7.8A flaw was found in the Xorg-x11-server. An out-of-bounds access issue can occur in the ProcXkbSetGeometry function due ...
CVE-2022-2308MEDIUM6.5A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of ...
CVE-2022-2256LOW3.8A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This fla...
CVE-2022-2238MEDIUM6.5A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query...
CVE-2022-23452MEDIUM4.9An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different ...
CVE-2022-1902HIGH8.8A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized i...
CVE-2022-1729HIGH7A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain ...
CVE-2022-1677MEDIUM6.3In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a m...
CVE-2022-1632MEDIUM6.5An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate expli...
CVE-2022-1615MEDIUM5.5In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
CVE-2022-36773HIGH8.1IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when proc...
CVE-2022-34380HIGH8.2Dell CloudLink 7.1.3 and all earlier versions contain an Authentication Bypass Using an Alternate Path or Channel Vulner...
CVE-2022-34379CRITICAL9.8Dell EMC CloudLink 7.1.2 and all prior versions contain an Authentication Bypass Vulnerability. A remote attacker, with ...
CVE-2022-34372CRITICAL9.1Dell PowerProtect Cyber Recovery versions before 19.11.0.2 contain an authentication bypass vulnerability. A remote unau...
CVE-2022-30614HIGH7.5IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to a denial of service via email flooding caused by sendin...
CVE-2022-3061MEDIUM5.5Found Linux Kernel flaw in the i740 driver. The Userspace program could pass any values to the driver through ioctl() in...
CVE-2022-36583MEDIUM6.1DedeCMS V5.7.97 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/co_do.php via the...
CVE-2022-2996HIGH7.4A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate wou...
CVE-2022-36796MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in CallRail, Inc. CallRail ...
CVE-2022-36373HIGH8.8Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Simon Ward MP3 jPlayer plugin <= 2.7.3 at WordPress.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now