CVEs from 2022

8,004 normalized CVEs published or assigned in this year.

Total
8,004
critical
critical 88
high
high 1,240
medium
medium 887
low
low 23
% Critical
1.1%
% with KEV
1.6%
% with exploit
1.6%

Top vendors

Top products

  • jdk 116
  • jre 109
  • openjdk 100
  • zulu 82
  • graalvm 74
  • cloud_secure_agent 35
  • oncommand_insight 34
  • cloud_insights_acquisition_unit 34
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2022-24706 critical 10.0 4y ago Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges. archsuse
CVE-2022-26485 critical 10.0 4y ago Critical: firefox security update susedebianrockylinux
CVE-2022-2586 medium 7.0 4y ago Moderate: kernel security, bug fix, and enhancement update redhatalmalinuxrockylinuxsuse+1
CVE-2022-32893 medium 7.0 4y ago Moderate: webkit2gtk3 security update archredhatsuserockylinux+1
CVE-2022-22620 medium 7.0 4y ago Moderate: webkit2gtk3 security, bug fix, and enhancement update archsuserockylinuxdebian+1
CVE-2022-36537 unknown 1.5 4y ago ZK Framework vulnerable to malicious POST java
CVE-2022-33891 unknown 1.5 4y ago Apache Spark UI can allow impersonation if ACLs enabled susejavapython
CVE-2022-22963 unknown 1.5 4y ago Spring Cloud Function Code Injection with a specially crafted SpEL as a routing expression java
CVE-2022-22965 unknown 1.5 4y ago Remote Code Execution in Spring Framework debianjava
CVE-2022-22947 unknown 1.5 4y ago Spring Cloud Gateway vulnerable to Code Injection when Gateway Actuator endpoint enabled, exposed, unsecured java