CVEs from 2022

5,367 normalized CVEs published or assigned in this year.

Total
5,367
critical
critical 88
high
high 1,220
medium
medium 938
low
low 24
% Critical
1.6%
% with KEV
2.4%
% with exploit
3.3%

Top products

  • jdk 116
  • jre 109
  • openjdk 100
  • zulu 82
  • graalvm 74
  • cloud_secure_agent 35
  • oncommand_insight 34
  • cloud_insights_acquisition_unit 34
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-50244 unknown In the Linux kernel, the following vulnerability has been resolved: cxl: fix possible null-ptr-deref in cxl_pci_init_afu|adapter() If device_register() fails in cxl_pci_afu|adapter(), the device is…
CVE-2022-50270 unknown In the Linux kernel, the following vulnerability has been resolved: f2fs: fix the assign logic of iocb commit 18ae8d12991b ("f2fs: show more DIO information in tracepoint") introduces iocb field in…
CVE-2022-50282 unknown In the Linux kernel, the following vulnerability has been resolved: chardev: fix error handling in cdev_device_add() While doing fault injection test, I got the following report: ------------[ cut…
CVE-2022-50283 unknown In the Linux kernel, the following vulnerability has been resolved: mtd: core: add missing of_node_get() in dynamic partitions code This fixes unbalanced of_node_put(): [ 1.078910] 6 cmdlinepart…
CVE-2022-50292 unknown In the Linux kernel, the following vulnerability has been resolved: drm/msm/dp: fix bridge lifetime Device-managed resources allocated post component bind must be tied to the lifetime of the aggreg…
CVE-2022-50296 unknown In the Linux kernel, the following vulnerability has been resolved: UM: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS is selected, cp…
CVE-2022-50309 unknown In the Linux kernel, the following vulnerability has been resolved: media: xilinx: vipp: Fix refcount leak in xvip_graph_dma_init of_get_child_by_name() returns a node pointer with refcount increme…
CVE-2022-50310 unknown In the Linux kernel, the following vulnerability has been resolved: ip6mr: fix UAF issue in ip6mr_sk_done() when addrconf_init_net() failed If the initialization fails in calling addrconf_init_net(…
CVE-2022-50314 unknown In the Linux kernel, the following vulnerability has been resolved: nbd: Fix hung when signal interrupts nbd_start_device_ioctl() syzbot reported hung task [1]. The following program is a simplifi…
CVE-2022-50315 unknown In the Linux kernel, the following vulnerability has been resolved: ata: ahci: Match EM_MAX_SLOTS with SATA_PMP_MAX_PORTS UBSAN complains about array-index-out-of-bounds: [ 1.980703] kernel: UBSAN:…
CVE-2022-4427 unknown Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition allows SQL Injection via TicketSearch Webservice This issue affects OTRS: from 7.0.1 before 7.0.40 Patch 1,…
CVE-2022-21821 unknown NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted …
CVE-2022-32546 unknown A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a n…
CVE-2022-48541 unknown A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command.
CVE-2022-27920 unknown libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0.
CVE-2022-3041 unknown Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2022-34009 unknown Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product …
CVE-2022-28506 unknown There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.
CVE-2022-2000 unknown Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
CVE-2022-48954 unknown In the Linux kernel, the following vulnerability has been resolved: s390/qeth: fix use-after-free in hsci KASAN found that addr was dereferenced after br2dev_event_work was freed. ================…
CVE-2022-0114 unknown Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial por…
CVE-2022-0305 unknown Inappropriate implementation in Service Worker API in Google Chrome prior to 97.0.4692.99 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTM…
CVE-2022-0454 unknown Heap buffer overflow in ANGLE in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2022-0460 unknown Use after free in Window Dialogue in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2022-0804 unknown Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2022-48998 unknown In the Linux kernel, the following vulnerability has been resolved: powerpc/bpf/32: Fix Oops on tail call tests test_bpf tail call tests end up as: test_bpf: #0 Tail call leaf jited:1 85 PASS …
CVE-2022-49079 unknown In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: traverse devices under chunk_mutex in btrfs_can_activate_zone btrfs_can_activate_zone() can be called with the devi…
CVE-2022-49073 unknown In the Linux kernel, the following vulnerability has been resolved: ata: sata_dwc_460ex: Fix crash due to OOB write the driver uses libata's "tag" values from in various arrays. Since the mentioned…
CVE-2022-49783 unknown In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Drop fpregs lock before inheriting FPU permissions Mike Galbraith reported the following against an old fork of preempt-…
CVE-2022-49352 unknown In the Linux kernel, the following vulnerability has been resolved: ext4: fix warning in ext4_handle_inode_extension We got issue as follows: EXT4-fs error (device loop0) in ext4_reserve_inode_writ…
CVE-2022-50320 unknown In the Linux kernel, the following vulnerability has been resolved: ACPI: tables: FPDT: Don't call acpi_os_map_memory() on invalid phys address On a Packard Bell Dot SC (Intel Atom N2600 model) the…
CVE-2022-49812 unknown In the Linux kernel, the following vulnerability has been resolved: bridge: switchdev: Fix memory leaks when changing VLAN protocol The bridge driver can offload VLANs to the underlying hardware ei…
CVE-2022-50257 unknown In the Linux kernel, the following vulnerability has been resolved: xen/gntdev: Prevent leaking grants Prior to this commit, if a grant mapping operation failed partially, some of the entries in th…
CVE-2022-2622 unknown Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a crafted file.
CVE-2022-3307 unknown Use after free in media in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2022-49957 unknown 1y ago In the Linux kernel, the following vulnerability has been resolved: kcm: fix strp_init() order and cleanup strp_init() is called just a few lines above this csk->sk_user_data check, it also initial…
CVE-2022-41137 unknown 2y ago Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore
CVE-2022-23553 unknown 2y ago Alpine allows URL access filter bypass
CVE-2022-23554 unknown 2y ago Alpine allows Authentication Filter bypass
CVE-2022-48833 unknown 2y ago In the Linux kernel, the following vulnerability has been resolved: btrfs: skip reserved bytes warning on unmount after log cleanup failure After the recent changes made by commit c2e39305299f01 ("…
CVE-2022-29946 unknown 2y ago NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one sc…
CVE-2022-30636 unknown 2y ago httpTokenCacheKey uses path.Base to extract the expected HTTP-01 token value to lookup in the DirCache implementation. On Windows, path.Base acts differently to filepath.Base, since Windows uses a di…
CVE-2022-47894 unknown 2y ago Apache Zeppelin SAP: connecting to a malicious SAP server allowed it to perform XXE
CVE-2022-4963 unknown 2y ago SQL injection in Folio Spring Module Core
CVE-2022-34321 unknown 2y ago Apache Pulsar: Improper Authentication for Pulsar Proxy Statistics Endpoint
CVE-2022-45320 unknown 2y ago Privilege escalation in Liferay Portal
CVE-2022-3328 unknown 2y ago Race condition in snap-confine's must_mkdir_and_open_with_perms()
CVE-2022-45135 unknown 3y ago Apache Cocoon SQL Injection vulnerability
CVE-2022-2232 unknown 3y ago Keycloak vulnerable to LDAP Injection on UsernameForm Login
CVE-2022-41678 unknown 3y ago Apache ActiveMQ Deserialization of Untrusted Data vulnerability
CVE-2022-46337 unknown 3y ago Apache Derby: LDAP injection vulnerability in authenticator
CVE-2022-4245 unknown 3y ago codehaus-plexus vulnerable to XML injection
CVE-2022-4244 unknown 3y ago plexus-codehaus vulnerable to directory traversal
CVE-2022-28357 unknown 3y ago NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
CVE-2022-1415 unknown 3y ago Drools Core Deserialization of Untrusted Data vulnerability
CVE-2022-44729 unknown 3y ago Apache XML Graphics Batik Server-Side Request Forgery vulnerability
CVE-2022-46751 unknown 3y ago Apache Ivy External Entity Reference vulnerability
CVE-2022-41401 unknown 3y ago OpenRefine Server-Side Request Forgery vulnerability
CVE-2022-40896 unknown 3y ago A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
CVE-2022-42009 unknown 3y ago Apache Ambari Expression Language Injection vulnerability
CVE-2022-45855 unknown 3y ago Apache Ambari Expression Language Injection vulnerability
CVE-2022-45048 unknown 3y ago Apache Ranger code execution vulnerability in policy expressions
CVE-2022-45802 unknown 3y ago Apache StreamPark Path Traversal vulnerability
CVE-2022-46365 unknown 3y ago Apache StreamPark Improper Input Validation vulnerability
CVE-2022-24697 unknown 3y ago Apache Kylin vulnerable to remote code execution
CVE-2022-4361 unknown 3y ago Keycloak vulnerable to cross-site scripting when validating URI-schemes on SAML and OIDC
CVE-2022-46907 unknown 3y ago Apache JSPWiki vulnerable to cross-site scripting on several plugins
CVE-2022-47937 unknown 3y ago Apache Sling Commons JSON bundle vulnerable to Improper Input Validation
CVE-2022-45801 unknown 3y ago Apache StreamPark LDAP Injection vulnerability
CVE-2022-45064 unknown 3y ago Apache Sling Engine vulnerable to cross-site scripting (XSS) that can lead to privilege escalation
CVE-2022-41918 unknown 3y ago OpenSearch has issue with fine-grained access control of indices backing data streams
CVE-2022-3277 unknown 3y ago An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates re…
CVE-2022-1274 unknown 3y ago HTML Injection in Keycloak Admin REST API
CVE-2022-4137 unknown 3y ago Keycloak Cross-site Scripting on OpenID connect login service
CVE-2022-1438 unknown 3y ago Keycloak vulnerable to Cross-site Scripting
CVE-2022-39228 unknown 3y ago vantage6 vulnerable to Observable Response Discrepancy
CVE-2022-4492 unknown 3y ago Undertow client not checking server identity presented by server certificate in https connections
CVE-2022-42735 unknown 3y ago Privilege escalation in Apache ShenYu
CVE-2022-4903 unknown 3y ago CodenameOne Pending Intent vulnerability
CVE-2022-24894 unknown 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers…
CVE-2022-24895 unknown 3y ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the…
CVE-2022-44644 unknown 3y ago Apache Linkis vulnerable to Exposure of Sensitive Information
CVE-2022-44645 unknown 3y ago Apache Linkis contains Deserialization of Untrusted Data
CVE-2022-2712 unknown 3y ago Path Traversal In Eclipse GlassFish
CVE-2022-47951 unknown 3y ago An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0…
CVE-2022-25894 unknown 3y ago Remote Code Execution in com.bstek.uflo:uflo-core
CVE-2022-47042 unknown 3y ago Arbitrary file write in net.mingsoft:ms-mcms
CVE-2022-47105 unknown 3y ago Jeecg-boot is vulnerable to SQL injection
CVE-2022-47950 unknown 3y ago An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file c…
CVE-2022-25901 unknown 3y ago cookiejar Regular Expression Denial of Service via Cookie.parse function
CVE-2022-23532 unknown 3y ago org.neo4j.procedure:apoc Path Traversal Vulnerability
CVE-2022-3143 unknown 3y ago Wildfly-elytron possibly vulnerable to timing attacks via use of unsafe comparator
CVE-2022-24913 unknown 3y ago Java Merge-sort Insecure Temporary File vulnerability
CVE-2022-46176 unknown 3y ago Cargo is a Rust package manager. The Rust Security Response WG was notified that Cargo did not perform SSH host key verification when cloning indexes and dependencies via SSH. An attacker could explo…
CVE-2022-46769 unknown 3y ago Apache Sling App CMS vulnerable to reflected Cross-site Scripting
CVE-2022-45787 unknown 3y ago Apache James MIME4J vulnerable to information disclosure to local users
CVE-2022-45935 unknown 3y ago Apache James server allows an attacker with local access to access private user data in transit
CVE-2022-45875 unknown 3y ago Apache DolphinScheduler vulnerable to Improper Input Validation
CVE-2022-38723 unknown 4y ago Gravitee API Management contains Path Traversal
CVE-2022-45143 unknown 4y ago The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from use…