CVEs from 2022
Total
8,251
critical
critical 88
high
high 1,240
medium
medium 887
low
low 23
% Critical
1.1%
% with KEV
1.6%
% with exploit
1.6%
Top products
- jdk 116
- jre 109
- openjdk 100
- zulu 82
- graalvm 74
- cloud_secure_agent 35
- oncommand_insight 34
- cloud_insights_acquisition_unit 34
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2022-39320 | medium | — | 5.5 | 3y ago | Moderate: freerdp security update | |
| CVE-2022-39316 | medium | — | 5.5 | 3y ago | Moderate: freerdp security update | |
| CVE-2022-3551 | medium | — | 5.5 | 3y ago | Moderate: xorg-x11-server-Xwayland security update | |
| CVE-2022-2928 | medium | — | 5.5 | 3y ago | Moderate: dhcp security and enhancement update | |
| CVE-2022-30784 | medium | — | 5.5 | 3y ago | Moderate: libguestfs-winsupport security update | |
| CVE-2022-4172 | medium | — | 5.5 | 3y ago | Moderate: qemu-kvm security, bug fix, and enhancement update | |
| CVE-2022-44793 | medium | — | 5.5 | 3y ago | Moderate: net-snmp security and bug fix update | |
| CVE-2022-34301 | medium | — | 5.5 | 3y ago | Moderate: fwupd security and bug fix update | |
| CVE-2022-41860 | medium | — | 5.5 | 3y ago | Moderate: freeradius security and bug fix update | |
| CVE-2022-46343 | medium | — | 5.5 | 3y ago | Moderate: xorg-x11-server-Xwayland security update | |
| CVE-2022-41973 | medium | — | 5.5 | 3y ago | Moderate: device-mapper-multipath security and bug fix update | |
| CVE-2022-39283 | medium | — | 5.5 | 3y ago | Moderate: freerdp security update | |
| CVE-2022-37454 | medium | — | 5.5 | 3y ago | Moderate: php security update | |
| CVE-2022-2625 | medium | — | 5.5 | 3y ago | Moderate: postgresql security update | |
| CVE-2022-41862 | medium | — | 5.5 | 3y ago | Moderate: postgresql security update | |
| CVE-2022-4899 | medium | — | 5.5 | 3y ago | Moderate: mysql security update | |
| CVE-2022-31628 | medium | — | 5.5 | 3y ago | Moderate: php security update | |
| CVE-2022-37436 | medium | — | 5.5 | 3y ago | Moderate: httpd security and bug fix update | |
| CVE-2022-47024 | medium | — | 5.5 | 3y ago | Moderate: vim security update | |
| CVE-2022-31630 | medium | — | 5.5 | 3y ago | Moderate: php security update | |
| CVE-2022-31631 | medium | — | 5.5 | 3y ago | Moderate: php security update | |
| CVE-2022-31629 | medium | — | 5.5 | 3y ago | Moderate: php security update | |
| CVE-2022-45061 | medium | — | 5.5 | 3y ago | Moderate: python39:3.9 and python39-devel:3.9 security update | |
| CVE-2022-45873 | medium | — | 5.5 | 3y ago | Moderate: systemd security update | |
| CVE-2022-36760 | medium | — | 5.5 | 3y ago | Moderate: httpd security and bug fix update | |
| CVE-2022-4415 | medium | — | 5.5 | 3y ago | Moderate: systemd security update | |
| CVE-2022-40897 | medium | — | 5.5 | 3y ago | Moderate: python-setuptools security update | |
| CVE-2022-48303 | medium | — | 5.5 | 3y ago | Moderate: tar security update | |
| CVE-2022-4203 | medium | — | 5.5 | 3y ago | Moderate: openssl security and bug fix update | |
| CVE-2022-2953 | medium | — | 5.5 | 3y ago | Moderate: libtiff security update | |
| CVE-2022-32221 | medium | — | 5.5 | 3y ago | Moderate: curl security update | |
| CVE-2022-42011 | medium | — | 5.5 | 3y ago | Moderate: dbus security update | |
| CVE-2022-40304 | medium | — | 5.5 | 3y ago | Moderate: libxml2 security update | |
| CVE-2022-3715 | medium | — | 5.5 | 3y ago | Moderate: bash security update | |
| CVE-2022-41717 | medium | — | 5.5 | 3y ago | Moderate: container-tools:4.0 security and bug fix update | |
| CVE-2022-27664 | medium | — | 5.5 | 3y ago | Moderate: git-lfs security and bug fix update | |
| CVE-2022-2057 | medium | — | 5.5 | 3y ago | Moderate: libtiff security update | |
| CVE-2022-42010 | medium | — | 5.5 | 3y ago | Moderate: dbus security update | |
| CVE-2022-3821 | medium | — | 5.5 | 3y ago | Moderate: systemd security update | |
| CVE-2022-26307 | medium | — | 5.5 | 3y ago | Moderate: libreoffice security update | |
| CVE-2022-26305 | medium | — | 5.5 | 3y ago | Moderate: libreoffice security update | |
| CVE-2022-43680 | medium | — | 5.5 | 3y ago | In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. | |
| CVE-2022-2519 | medium | — | 5.5 | 3y ago | Moderate: libtiff security update | |
| CVE-2022-41715 | medium | — | 5.5 | 3y ago | Moderate: git-lfs security and bug fix update | |
| CVE-2022-3140 | medium | — | 5.5 | 3y ago | Moderate: libreoffice security update | |
| CVE-2022-26306 | medium | — | 5.5 | 3y ago | Moderate: libreoffice security update | |
| CVE-2022-2880 | medium | — | 5.5 | 3y ago | Moderate: git-lfs security and bug fix update | |
| CVE-2022-2058 | medium | — | 5.5 | 3y ago | Moderate: libtiff security update | |
| CVE-2022-2520 | medium | — | 5.5 | 3y ago | Moderate: libtiff security update | |
| CVE-2022-2521 | medium | — | 5.5 | 3y ago | Moderate: libtiff security update | |
| CVE-2022-42012 | medium | — | 5.5 | 3y ago | Moderate: dbus security update | |
| CVE-2022-40303 | medium | — | 5.5 | 3y ago | Moderate: libxml2 security update | |
| CVE-2022-2056 | medium | — | 5.5 | 3y ago | Moderate: libtiff security update | |
| CVE-2022-31197 | medium | — | 5.5 | 3y ago | Moderate: postgresql-jdbc security update | |
| CVE-2022-2879 | medium | — | 5.5 | 3y ago | Moderate: Image Builder security, bug fix, and enhancement update | |
| CVE-2022-4144 | medium | — | 5.5 | 3y ago | Moderate: virt:rhel and virt-devel:rhel security and bug fix update | |
| CVE-2022-2868 | medium | — | 5.5 | 3y ago | Moderate: libtiff security update | |
| CVE-2022-2869 | medium | — | 5.5 | 3y ago | Moderate: libtiff security update | |
| CVE-2022-2867 | medium | — | 5.5 | 3y ago | Moderate: libtiff security update | |
| CVE-2022-3517 | medium | — | 5.5 | 4y ago | Moderate: nodejs:16 security, bug fix, and enhancement update | |
| CVE-2022-43548 | medium | — | 5.5 | 4y ago | Moderate: nodejs:16 security, bug fix, and enhancement update | |
| CVE-2022-45442 | medium | — | 5.5 | 4y ago | Moderate: pcs security update | |
| CVE-2022-24999 | medium | — | 5.5 | 4y ago | Moderate: nodejs:14 security, bug fix, and enhancement update | |
| CVE-2022-48918 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: iwlwifi: mvm: check debugfs_dir ptr before use When "debugfs=off" is used on the kernel command line, iwiwifi's mvm module uses a… | |
| CVE-2022-49389 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: usb: usbip: fix a refcount leak in stub_probe() usb_get_dev() is called in stub_device_alloc(). When stub_probe() fails after tha… | |
| CVE-2022-30698 | medium | — | 5.5 | 4y ago | Moderate: unbound security, bug fix, and enhancement update | |
| CVE-2022-48765 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: KVM: LAPIC: Also cancel preemption timer during SET_LAPIC The below warning is splatting during guest reboot. ------------[ cu… | |
| CVE-2022-26719 | medium | — | 5.5 | 4y ago | Moderate: webkit2gtk3 security and bug fix update | |
| CVE-2022-48738 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Reject out of bounds values in snd_soc_put_volsw() We don't currently validate that the values being set are within th… | |
| CVE-2022-28614 | medium | — | 5.5 | 4y ago | Moderate: httpd security, bug fix, and enhancement update | |
| CVE-2022-1048 | medium | — | 5.5 | 4y ago | Moderate: kernel-rt security and bug fix update | |
| CVE-2022-22624 | medium | — | 5.5 | 4y ago | Moderate: webkit2gtk3 security and bug fix update | |
| CVE-2022-49272 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix potential AB/BA lock with buffer_mutex and mmap_lock syzbot caught a potential deadlock between the PCM runtime->b… | |
| CVE-2022-49086 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix leak of nested actions While parsing user-provided actions, openvswitch module may dynamically allocate mem… | |
| CVE-2022-22719 | medium | — | 5.5 | 4y ago | Moderate: httpd security, bug fix, and enhancement update | |
| CVE-2022-29404 | medium | — | 5.5 | 4y ago | Moderate: httpd security, bug fix, and enhancement update | |
| CVE-2022-22629 | medium | — | 5.5 | 4y ago | Moderate: webkit2gtk3 security and bug fix update | |
| CVE-2022-32792 | medium | — | 5.5 | 4y ago | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, watchOS 8.7, tvOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing malici… | |
| CVE-2022-26710 | medium | — | 5.5 | 4y ago | Moderate: webkit2gtk3 security and bug fix update | |
| CVE-2022-27405 | medium | — | 5.5 | 4y ago | Moderate: freetype security update | |
| CVE-2022-1998 | medium | — | 5.5 | 4y ago | Moderate: kernel security, bug fix, and enhancement update | |
| CVE-2022-1184 | medium | — | 5.5 | 4y ago | Moderate: kernel security, bug fix, and enhancement update | |
| CVE-2022-2320 | medium | — | 5.5 | 4y ago | Moderate: xorg-x11-server security and bug fix update | |
| CVE-2022-2989 | medium | — | 5.5 | 4y ago | Moderate: buildah security and bug fix update | |
| CVE-2022-48735 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix UAF of leds class devs at unbinding The LED class devices that are created by HD-audio codec drivers are registere… | |
| CVE-2022-32891 | medium | — | 5.5 | 4y ago | The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16, watchOS 9, iOS 16. Visiting a website that frames malicious content may lead to UI spoofing. | |
| CVE-2022-49152 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: XArray: Fix xas_create_range() when multi-order entry present If there is already an entry present that is of order >= XA_CHUNK_S… | |
| CVE-2022-26716 | medium | — | 5.5 | 4y ago | Moderate: webkit2gtk3 security and bug fix update | |
| CVE-2022-49561 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: re-fetch conntrack after insertion In case the conntrack is clashing, insertion can free skb->_nfct and set… | |
| CVE-2022-50187 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: ath11k: fix netdev open race Make sure to allocate resources needed before registering the device. This specifically avoids havi… | |
| CVE-2022-0924 | medium | — | 5.5 | 4y ago | Moderate: libtiff security update | |
| CVE-2022-49606 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Fix sleep from invalid context BUG Taking the qos_mutex to process RoCEv2 QP's on netdev events causes a kernel splat… | |
| CVE-2022-0854 | medium | — | 5.5 | 4y ago | Moderate: kernel-rt security and bug fix update | |
| CVE-2022-50115 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-topology: Prevent double freeing of ipc_control_data via load_bytes We have sanity checks for byte controls and i… | |
| CVE-2022-29162 | medium | — | 5.5 | 4y ago | Moderate: container-tools:4.0 security and bug fix update | |
| CVE-2022-2319 | medium | — | 5.5 | 4y ago | Moderate: xorg-x11-server security and bug fix update | |
| CVE-2022-49404 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: RDMA/hfi1: Fix potential integer multiplication overflow errors When multiplying of different types, an overflow is possible even… | |
| CVE-2022-49291 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Fix races among concurrent hw_params and hw_free calls Currently we have neither proper check nor protection against t… | |
| CVE-2022-1355 | medium | — | 5.5 | 4y ago | Moderate: libtiff security update | |
| CVE-2022-49534 | medium | — | 5.5 | 4y ago | In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Protect memory leak for NPIV ports sending PLOGI_RJT There is a potential memory leak in lpfc_ignore_els_cmpl() and l… |