2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-44018 | HIGH | 7.5 | 0.8% | Jan 26, 2023 | In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer ... |
| CVE-2022-43997 | HIGH | 7.8 | 0.4% | Jan 26, 2023 | Incorrect access control in Aternity agent in Riverbed Aternity before 12.1.4.27 allows for local privilege escalation. ... |
| CVE-2022-43917 | HIGH | 7.5 | 0.5% | Jan 26, 2023 | IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that co... |
| CVE-2022-43864 | HIGH | 7.5 | 2.0% | Jan 26, 2023 | IBM Business Automation Workflow 22.0.2 could allow a remote attacker to traverse directories on the system. An attacke... |
| CVE-2022-42330 | HIGH | 7.5 | 1.4% | Jan 26, 2023 | Guests can cause Xenstore crash via soft reset When a guest issues a "Soft Reset" (e.g. for performing a kexec) the libx... |
| CVE-2022-40035 | HIGH | 8.8 | 1.2% | Jan 26, 2023 | File Upload Vulnerability found in Rawchen Blog-ssm v1.0 allowing attackers to execute arbitrary commands and gain escal... |
| CVE-2022-3924 | HIGH | 7.5 | 16.4% | Jan 26, 2023 | This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-cl... |
| CVE-2022-3736 | HIGH | 7.5 | 50.2% | Jan 26, 2023 | BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to... |
| CVE-2022-3488 | HIGH | 7.5 | 19.0% | Jan 26, 2023 | Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first... |
| CVE-2022-3094 | HIGH | 7.5 | 13.1% | Jan 26, 2023 | Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `... |
| CVE-2022-38775 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged... |
| CVE-2022-38774 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which co... |
| CVE-2022-34405 | HIGH | 7.3 | 0.3% | Jan 26, 2023 | An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious use... |
| CVE-2022-31710 | HIGH | 7.5 | 1.5% | Jan 26, 2023 | vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger t... |
| CVE-2022-27508 | HIGH | 7.5 | 1.0% | Jan 26, 2023 | Unauthenticated denial of service |
| CVE-2022-25927 | HIGH | 7.5 | 1.7% | Jan 26, 2023 | Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regul... |
| CVE-2022-25882 | HIGH | 7.5 | 1.6% | Jan 26, 2023 | Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tenso... |
| CVE-2022-25350 | HIGH | 7.8 | 1.2% | Jan 26, 2023 | All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper ... |
| CVE-2022-22462 | HIGH | 7.5 | 0.5% | Jan 26, 2023 | IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker than expected cryptogra... |
| CVE-2022-21810 | HIGH | 7.8 | 1.2% | Jan 26, 2023 | All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanit... |
| CVE-2022-21192 | HIGH | 7.5 | 1.3% | Jan 26, 2023 | All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other ... |
| CVE-2022-20493 | HIGH | 7.8 | 0.2% | Jan 26, 2023 | In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. T... |
| CVE-2022-20492 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource ... |
| CVE-2022-20490 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resou... |
| CVE-2022-20489 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now