2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22952 | CRITICAL | 9.1 | 1.4% | Mar 23, 2022 | VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.... |
| CVE-2022-22951 | CRITICAL | 9.1 | 21.9% | Mar 23, 2022 | VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.... |
| CVE-2022-1030 | HIGH | 8.8 | 1.5% | Mar 23, 2022 | Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command inj... |
| CVE-2022-0996 | MEDIUM | 6.5 | 1.5% | Mar 23, 2022 | A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause impr... |
| CVE-2022-0981 | HIGH | 8.8 | 1.1% | Mar 23, 2022 | A flaw was found in Quarkus. The state and potentially associated permissions can leak from one web request to another i... |
| CVE-2022-0889 | MEDIUM | 6.1 | 0.7% | Mar 23, 2022 | The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing... |
| CVE-2022-0888 | CRITICAL | 9.8 | 39.4% | Mar 23, 2022 | The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient in... |
| CVE-2022-0854 | MEDIUM | 5.5 | 0.5% | Mar 23, 2022 | A memory leak flaw was found in the Linux kernel’s DMA subsystem, in the way a user calls DMA_FROM_DEVICE. This flaw all... |
| CVE-2022-0834 | MEDIUM | 5.4 | 0.5% | Mar 23, 2022 | The Amelia WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the l... |
| CVE-2022-0750 | MEDIUM | 5.4 | 4.4% | Mar 23, 2022 | The Photoswipe Masonry Gallery WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and s... |
| CVE-2022-26243 | HIGH | 7.5 | 1.2% | Mar 23, 2022 | Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow in the setSmartPowerManagement function. |
| CVE-2022-22316 | MEDIUM | 6.5 | 0.9% | Mar 23, 2022 | IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service due to... |
| CVE-2022-23242 | MEDIUM | 4.2 | 0.2% | Mar 23, 2022 | TeamViewer Linux versions before 15.28 do not properly execute a deletion command for the connection password in case of... |
| CVE-2022-0862 | MEDIUM | 5.3 | 0.7% | Mar 23, 2022 | A lack of password change protection vulnerability in a depreciated API of McAfee Enterprise ePolicy Orchestrator (ePO) ... |
| CVE-2022-0861 | LOW | 3.8 | 0.4% | Mar 23, 2022 | A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a rem... |
| CVE-2022-0859 | MEDIUM | 6.7 | 0.2% | Mar 23, 2022 | McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to a... |
| CVE-2022-0858 | MEDIUM | 4.7 | 0.8% | Mar 23, 2022 | A cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allow... |
| CVE-2022-0857 | MEDIUM | 6.1 | 0.7% | Mar 23, 2022 | A reflected cross-site scripting (XSS) vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Updat... |
| CVE-2022-0886 | — | — | — | Mar 23, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-27666. Reason: This candidate is a reservation d... |
| CVE-2022-0842 | MEDIUM | 4.9 | 0.7% | Mar 23, 2022 | A blind SQL injection vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a rem... |
| CVE-2022-0635 | HIGH | 7.5 | 1.3% | Mar 23, 2022 | Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named proce... |
| CVE-2022-0396 | MEDIUM | 5.3 | 2.6% | Mar 23, 2022 | BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. S... |
| CVE-2022-1033 | HIGH | 7.8 | 0.9% | Mar 23, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6. |
| CVE-2022-27666 | HIGH | 7.8 | 5.5% | Mar 23, 2022 | A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw... |
| CVE-2022-25518 | MEDIUM | 6.5 | 0.7% | Mar 22, 2022 | In CMDBuild from version 3.0 to 3.3.2 payload requests are saved in a temporary log table, which allows attackers with d... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now