2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27634 | HIGH | 7.2 | 1.3% | May 5, 2022 | On 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, BIG-IP APM does not properly validate config... |
| CVE-2022-27588 | CRITICAL | 9.8 | 1.2% | May 5, 2022 | We have already fixed this vulnerability in the following versions of QVR: QVR 5.1.6 build 20220401 and later |
| CVE-2022-27495 | MEDIUM | 6.5 | 0.3% | May 5, 2022 | On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay net... |
| CVE-2022-27230 | MEDIUM | 6.1 | 0.5% | May 5, 2022 | On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP APM, and F5 BIG-IP Guided Configurati... |
| CVE-2022-27189 | HIGH | 7.5 | 0.9% | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13... |
| CVE-2022-27182 | MEDIUM | 5.3 | 0.8% | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6... |
| CVE-2022-27181 | MEDIUM | 5.3 | 0.8% | May 5, 2022 | On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6... |
| CVE-2022-26890 | HIGH | 7.5 | 0.9% | May 5, 2022 | On F5 BIG-IP Advanced WAF, ASM, and APM 16.1.x versions prior to 16.1.2.1, 15.1.x versions prior to 15.1.5, 14.1.x versi... |
| CVE-2022-26835 | MEDIUM | 4.9 | 1.7% | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13... |
| CVE-2022-26517 | HIGH | 7.5 | 0.7% | May 5, 2022 | On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, ... |
| CVE-2022-26415 | CRITICAL | 9.1 | 0.7% | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13... |
| CVE-2022-26372 | HIGH | 7.5 | 0.8% | May 5, 2022 | On F5 BIG-IP 15.1.x versions prior to 15.1.0.2, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and ... |
| CVE-2022-26370 | HIGH | 7.5 | 0.7% | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, ... |
| CVE-2022-26340 | MEDIUM | 4.9 | 0.4% | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13... |
| CVE-2022-26130 | MEDIUM | 5.3 | 0.8% | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, an... |
| CVE-2022-26071 | HIGH | 7.5 | 1.0% | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13... |
| CVE-2022-25990 | MEDIUM | 5.3 | 0.7% | May 5, 2022 | On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: So... |
| CVE-2022-25946 | MEDIUM | 6.5 | 0.4% | May 5, 2022 | On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP Advanced WAF, ASM, and ASM, and F5 BI... |
| CVE-2022-1468 | MEDIUM | 4.3 | 0.7% | May 5, 2022 | On all versions of 17.0.x, 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x on F5 BIG-IP, an authenticated iControl RE... |
| CVE-2022-1389 | MEDIUM | 4.3 | 0.3% | May 5, 2022 | On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP (fixed in 17.0.0), a cross-site reque... |
| CVE-2022-1388 | CRITICAL | 9.8 | 100.0% | May 5, 2022 | On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13... |
| CVE-2022-22434 | MEDIUM | 4.6 | 0.2% | May 5, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with physical access to create an API reque... |
| CVE-2022-22433 | HIGH | 7.5 | 1.0% | May 5, 2022 | IBM Robotic Process Automation 21.0.1 and 21.0.2 is vulnerable to External Service Interaction attack, caused by imprope... |
| CVE-2022-22415 | MEDIUM | 6.5 | 0.7% | May 5, 2022 | A vulnerability exists where an IBM Robotic Process Automation 21.0.1 regular user is able to obtain view-only access to... |
| CVE-2022-1516 | MEDIUM | 5.5 | 0.3% | May 5, 2022 | A NULL pointer dereference flaw was found in the Linux kernel’s X.25 set of standardized network protocols functionality... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now