CVEs from 2022

5,373 normalized CVEs published or assigned in this year.

Total
5,373
critical
critical 88
high
high 1,220
medium
medium 938
low
low 24
% Critical
1.6%
% with KEV
2.4%
% with exploit
3.3%

Top products

  • jdk 116
  • jre 109
  • openjdk 100
  • zulu 82
  • graalvm 74
  • cloud_secure_agent 35
  • oncommand_insight 34
  • cloud_insights_acquisition_unit 34
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-50521 unknown In the Linux kernel, the following vulnerability has been resolved: platform/x86: mxm-wmi: fix memleak in mxm_wmi_call_mx[ds|mx]() The ACPI buffer memory (out.pointer) returned by wmi_evaluate_meth…
CVE-2022-50522 unknown In the Linux kernel, the following vulnerability has been resolved: mcb: mcb-parse: fix error handing in chameleon_parse_gdd() If mcb_device_register() returns error in chameleon_parse_gdd(), the r…
CVE-2022-50523 unknown In the Linux kernel, the following vulnerability has been resolved: clk: rockchip: Fix memory leak in rockchip_clk_register_pll() If clk_register() fails, @pll->rate_table may have allocated memory…
CVE-2022-50524 unknown In the Linux kernel, the following vulnerability has been resolved: iommu/mediatek: Check return value after calling platform_get_resource() platform_get_resource() may return NULL pointer, we need…
CVE-2022-50525 unknown In the Linux kernel, the following vulnerability has been resolved: iommu/fsl_pamu: Fix resource leak in fsl_pamu_probe() The fsl_pamu_probe() returns directly when create_csd() failed, leaving irq…
CVE-2022-50526 unknown In the Linux kernel, the following vulnerability has been resolved: drm/msm/dp: fix memory corruption with too many bridges Add the missing sanity check on the bridge counter to avoid corrupting da…
CVE-2022-50529 unknown In the Linux kernel, the following vulnerability has been resolved: test_firmware: fix memory leak in test_firmware_init() When misc_register() failed in test_firmware_init(), the memory pointed by…
CVE-2022-50533 unknown In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: mlme: fix null-ptr deref on failed assoc If association to an AP without a link 0 fails, then we crash in tracing…
CVE-2022-50537 unknown In the Linux kernel, the following vulnerability has been resolved: firmware: raspberrypi: fix possible memory leak in rpi_firmware_probe() In rpi_firmware_probe(), if mbox_request_channel() fails,…
CVE-2022-50538 unknown In the Linux kernel, the following vulnerability has been resolved: vme: Fix error not catched in fake_init() In fake_init(), __root_device_register() is possible to fail but it's ignored, which ca…
CVE-2022-50539 unknown In the Linux kernel, the following vulnerability has been resolved: ARM: OMAP2+: omap4-common: Fix refcount leak bug In omap4_sram_init(), of_find_compatible_node() will return a node pointer with …
CVE-2022-50542 unknown In the Linux kernel, the following vulnerability has been resolved: media: si470x: Fix use-after-free in si470x_int_in_callback() syzbot reported use-after-free in si470x_int_in_callback() [1]. Th…
CVE-2022-50545 unknown In the Linux kernel, the following vulnerability has been resolved: r6040: Fix kmemleak in probe and remove There is a memory leaks reported by kmemleak: unreferenced object 0xffff888116111000 (…
CVE-2022-50551 unknown In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix potential shift-out-of-bounds in brcmf_fw_alloc_request() This patch fixes a shift-out-of-bounds in brcmfmac …
CVE-2022-50547 unknown In the Linux kernel, the following vulnerability has been resolved: media: solo6x10: fix possible memory leak in solo_sysfs_init() If device_register() returns error in solo_sysfs_init(), the name …
CVE-2022-3479 unknown A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash.
CVE-2022-50548 unknown In the Linux kernel, the following vulnerability has been resolved: media: i2c: hi846: Fix memory leak in hi846_parse_dt() If any of the checks related to the supported link frequencies fail, then …
CVE-2022-50552 unknown In the Linux kernel, the following vulnerability has been resolved: blk-mq: use quiesced elevator switch when reinitializing queues The hctx's run_work may be racing with the elevator switch when r…
CVE-2022-50888 unknown In the Linux kernel, the following vulnerability has been resolved: remoteproc: qcom: q6v5: Fix potential null-ptr-deref in q6v5_wcss_init_mmio() q6v5_wcss_init_mmio() will call platform_get_resour…
CVE-2022-42902 unknown In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lav…
CVE-2022-44641 unknown In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive us…
CVE-2022-45132 unknown In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configur…
CVE-2022-37186 unknown In LemonLDAP::NG before 2.0.15. some sessions are not deleted when they are supposed to be deleted according to the timeoutActivity setting. This can occur when there are at least two servers, and a …
CVE-2022-0856 unknown libcaca is affected by a Divide By Zero issue via img2txt, which allows a remote malicious user to cause a Denial of Service
CVE-2022-1050 unknown A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver to execute HW commands when shared buffers are not yet allocated, potentially …
CVE-2022-2962 unknown A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descriptor or copies the rx/tx frame, it doesn't check whether the destination address …
CVE-2022-36648 unknown The hardware emulation in the of_dpa_cmd_add_l2_flood of rocker device model in QEMU, as used in 7.0.0 and earlier, allows remote attackers to crash the host qemu and potentially execute code on the …
CVE-2022-3872 unknown An off-by-one read/write issue was found in the SDHCI device of QEMU. It occurs when reading/writing the Buffer Data Port Register in sdhci_read_dataport and sdhci_write_dataport, respectively, if da…
CVE-2022-27920 unknown libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0.
CVE-2022-49957 unknown 1y ago In the Linux kernel, the following vulnerability has been resolved: kcm: fix strp_init() order and cleanup strp_init() is called just a few lines above this csk->sk_user_data check, it also initial…
CVE-2022-41137 unknown 2y ago Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore
CVE-2022-23554 unknown 2y ago Alpine allows Authentication Filter bypass
CVE-2022-23553 unknown 2y ago Alpine allows URL access filter bypass
CVE-2022-48833 unknown 2y ago In the Linux kernel, the following vulnerability has been resolved: btrfs: skip reserved bytes warning on unmount after log cleanup failure After the recent changes made by commit c2e39305299f01 ("…
CVE-2022-29946 unknown 2y ago NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one sc…
CVE-2022-30636 unknown 2y ago httpTokenCacheKey uses path.Base to extract the expected HTTP-01 token value to lookup in the DirCache implementation. On Windows, path.Base acts differently to filepath.Base, since Windows uses a di…
CVE-2022-47894 unknown 2y ago Apache Zeppelin SAP: connecting to a malicious SAP server allowed it to perform XXE
CVE-2022-4963 unknown 2y ago SQL injection in Folio Spring Module Core
CVE-2022-34321 unknown 2y ago Apache Pulsar: Improper Authentication for Pulsar Proxy Statistics Endpoint
CVE-2022-45320 unknown 2y ago Privilege escalation in Liferay Portal
CVE-2022-3328 unknown 2y ago Race condition in snap-confine's must_mkdir_and_open_with_perms()
CVE-2022-45135 unknown 3y ago Apache Cocoon SQL Injection vulnerability
CVE-2022-2232 unknown 3y ago Keycloak vulnerable to LDAP Injection on UsernameForm Login
CVE-2022-41678 unknown 3y ago Apache ActiveMQ Deserialization of Untrusted Data vulnerability
CVE-2022-46337 unknown 3y ago Apache Derby: LDAP injection vulnerability in authenticator
CVE-2022-4244 unknown 3y ago plexus-codehaus vulnerable to directory traversal
CVE-2022-4245 unknown 3y ago codehaus-plexus vulnerable to XML injection
CVE-2022-28357 unknown 3y ago NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
CVE-2022-1415 unknown 3y ago Drools Core Deserialization of Untrusted Data vulnerability
CVE-2022-44729 unknown 3y ago Apache XML Graphics Batik Server-Side Request Forgery vulnerability
CVE-2022-46751 unknown 3y ago Apache Ivy External Entity Reference vulnerability
CVE-2022-41401 unknown 3y ago OpenRefine Server-Side Request Forgery vulnerability
CVE-2022-40896 unknown 3y ago A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
CVE-2022-42009 unknown 3y ago Apache Ambari Expression Language Injection vulnerability
CVE-2022-45855 unknown 3y ago Apache Ambari Expression Language Injection vulnerability
CVE-2022-45048 unknown 3y ago Apache Ranger code execution vulnerability in policy expressions
CVE-2022-46365 unknown 3y ago Apache StreamPark Improper Input Validation vulnerability
CVE-2022-45802 unknown 3y ago Apache StreamPark Path Traversal vulnerability
CVE-2022-24697 unknown 3y ago Apache Kylin vulnerable to remote code execution
CVE-2022-4361 unknown 3y ago Keycloak vulnerable to cross-site scripting when validating URI-schemes on SAML and OIDC
CVE-2022-46907 unknown 3y ago Apache JSPWiki vulnerable to cross-site scripting on several plugins
CVE-2022-47937 unknown 3y ago Apache Sling Commons JSON bundle vulnerable to Improper Input Validation
CVE-2022-45801 unknown 3y ago Apache StreamPark LDAP Injection vulnerability
CVE-2022-45064 unknown 3y ago Apache Sling Engine vulnerable to cross-site scripting (XSS) that can lead to privilege escalation
CVE-2022-41918 unknown 3y ago OpenSearch has issue with fine-grained access control of indices backing data streams
CVE-2022-3277 unknown 3y ago An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates re…
CVE-2022-1274 unknown 3y ago HTML Injection in Keycloak Admin REST API
CVE-2022-4137 unknown 3y ago Keycloak Cross-site Scripting on OpenID connect login service
CVE-2022-1438 unknown 3y ago Keycloak vulnerable to Cross-site Scripting
CVE-2022-39228 unknown 3y ago vantage6 vulnerable to Observable Response Discrepancy
CVE-2022-4492 unknown 3y ago Undertow client not checking server identity presented by server certificate in https connections
CVE-2022-42735 unknown 3y ago Privilege escalation in Apache ShenYu
CVE-2022-4903 unknown 3y ago CodenameOne Pending Intent vulnerability
CVE-2022-24894 unknown 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers…
CVE-2022-24895 unknown 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the…
CVE-2022-44645 unknown 3y ago Apache Linkis contains Deserialization of Untrusted Data
CVE-2022-44644 unknown 3y ago Apache Linkis vulnerable to Exposure of Sensitive Information
CVE-2022-2712 unknown 3y ago Path Traversal In Eclipse GlassFish
CVE-2022-47951 unknown 3y ago An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0…
CVE-2022-25894 unknown 3y ago Remote Code Execution in com.bstek.uflo:uflo-core
CVE-2022-47042 unknown 3y ago Arbitrary file write in net.mingsoft:ms-mcms
CVE-2022-47105 unknown 3y ago Jeecg-boot is vulnerable to SQL injection
CVE-2022-47950 unknown 3y ago An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file c…
CVE-2022-25901 unknown 3y ago cookiejar Regular Expression Denial of Service via Cookie.parse function
CVE-2022-23532 unknown 3y ago org.neo4j.procedure:apoc Path Traversal Vulnerability
CVE-2022-3143 unknown 3y ago Wildfly-elytron possibly vulnerable to timing attacks via use of unsafe comparator
CVE-2022-24913 unknown 3y ago Java Merge-sort Insecure Temporary File vulnerability
CVE-2022-46176 unknown 3y ago Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could explo…
CVE-2022-46769 unknown 3y ago Apache Sling App CMS vulnerable to reflected Cross-site Scripting
CVE-2022-45935 unknown 3y ago Apache James server allows an attacker with local access to access private user data in transit
CVE-2022-45787 unknown 3y ago Apache James MIME4J vulnerable to information disclosure to local users
CVE-2022-45875 unknown 3y ago Apache DolphinScheduler vulnerable to Improper Input Validation
CVE-2022-38723 unknown 3y ago Gravitee API Management contains Path Traversal
CVE-2022-45143 unknown 4y ago Apache Tomcat improperly escapes input from JsonErrorReportValve
CVE-2022-47551 unknown 4y ago Apiman has potential permissions bypass
CVE-2022-46178 unknown 4y ago Path Traversal In MeterSpere leads to upload file to any path
CVE-2022-40151 unknown 4y ago XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflow
CVE-2022-43396 unknown 4y ago Apache Kylin vulnerable to Command injection by Useless configuration
CVE-2022-44621 unknown 4y ago Apache Kylin vulnerable to Command injection by Diagnosis Controller
CVE-2022-41966 unknown 4y ago XStream can cause Denial of Service via stack overflow