2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22952CRITICAL9.1VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8....
CVE-2022-22951CRITICAL9.1VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8....
CVE-2022-1030HIGH8.8Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command inj...
CVE-2022-0996MEDIUM6.5A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause impr...
CVE-2022-0981HIGH8.8A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another i...
CVE-2022-0889MEDIUM6.1The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing...
CVE-2022-0888CRITICAL9.8The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient in...
CVE-2022-0854MEDIUM5.5A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw all...
CVE-2022-0834MEDIUM5.4The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the l...
CVE-2022-0750MEDIUM5.4The Photoswipe Masonry Gallery WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and s...
CVE-2022-26243HIGH7.5Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow in the setSmartPowerManagement function.
CVE-2022-22316MEDIUM6.5IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service due to...
CVE-2022-23242MEDIUM4.2TeamViewer Linux versions before 15.28 do not properly execute a deletion command for the connection password in case of...
CVE-2022-0862MEDIUM5.3A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) ...
CVE-2022-0861LOW3.8A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a rem...
CVE-2022-0859MEDIUM6.7McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to a...
CVE-2022-0858MEDIUM4.7A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allow...
CVE-2022-0857MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Updat...
CVE-2022-0886Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-27666. Reason: This candidate is a reservation d...
CVE-2022-0842MEDIUM4.9A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a rem...
CVE-2022-0635HIGH7.5Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named proce...
CVE-2022-0396MEDIUM5.3BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. S...
CVE-2022-1033HIGH7.8Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.
CVE-2022-27666HIGH7.8A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw...
CVE-2022-25518MEDIUM6.5In CMDBuild from version 3.0 to 3.3.2 payload requests are saved in a temporary log table, which allows attackers with d...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now