2022 CVE Vulnerabilities

27,525 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-44018HIGH7.5In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer ...
CVE-2022-43997HIGH7.8Incorrect access control in Aternity agent in Riverbed Aternity before 12.1.4.27 allows for local privilege escalation. ...
CVE-2022-43917HIGH7.5 IBM WebSphere Application Server 8.5 and 9.0 traditional container uses weaker than expected cryptographic keys that co...
CVE-2022-43864HIGH7.5 IBM Business Automation Workflow 22.0.2 could allow a remote attacker to traverse directories on the system. An attacke...
CVE-2022-42330HIGH7.5Guests can cause Xenstore crash via soft reset When a guest issues a "Soft Reset" (e.g. for performing a kexec) the libx...
CVE-2022-40035HIGH8.8File Upload Vulnerability found in Rawchen Blog-ssm v1.0 allowing attackers to execute arbitrary commands and gain escal...
CVE-2022-3924HIGH7.5This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-cl...
CVE-2022-3736HIGH7.5BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to...
CVE-2022-3488HIGH7.5Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first...
CVE-2022-3094HIGH7.5Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `...
CVE-2022-38775HIGH7.8An issue was discovered in the rollback feature of Elastic Endpoint Security for Windows, which could allow unprivileged...
CVE-2022-38774HIGH7.8An issue was discovered in the quarantine feature of Elastic Endpoint Security and Elastic Endgame for Windows, which co...
CVE-2022-34405HIGH7.3An improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious use...
CVE-2022-31710HIGH7.5vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger t...
CVE-2022-27508HIGH7.5Unauthenticated denial of service
CVE-2022-25927HIGH7.5Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regul...
CVE-2022-25882HIGH7.5Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tenso...
CVE-2022-25350HIGH7.8All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper ...
CVE-2022-22462HIGH7.5 IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker than expected cryptogra...
CVE-2022-21810HIGH7.8All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanit...
CVE-2022-21192HIGH7.5All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other ...
CVE-2022-20493HIGH7.8In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. T...
CVE-2022-20492HIGH7.8In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource ...
CVE-2022-20490HIGH7.8In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resou...
CVE-2022-20489HIGH7.8In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now