CVEs from 2022

5,738 normalized CVEs published or assigned in this year.

Total
5,738
critical
critical 88
high
high 1,220
medium
medium 938
low
low 24
% Critical
1.5%
% with KEV
2.3%
% with exploit
3.1%

Top products

  • jdk 116
  • jre 109
  • openjdk 100
  • zulu 82
  • graalvm 74
  • cloud_secure_agent 35
  • oncommand_insight 34
  • cloud_insights_acquisition_unit 34
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-42867 high 8.0 3y ago RHSA-2023:2834: webkit2gtk3 security and bug fix update (Important)
CVE-2022-49598 high 8.0 3y ago In the Linux kernel, the following vulnerability has been resolved: tcp: Fix data-races around sysctl_tcp_mtu_probing. While reading sysctl_tcp_mtu_probing, it can be changed concurrently. Thus, we…
CVE-2022-50136 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-50111 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-49328 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-49562 high 8.0 3y ago In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Use __try_cmpxchg_user() to update guest PTE A/D bits Use the recently introduced __try_cmpxchg_user() to update guest …
CVE-2022-49345 high 8.0 3y ago In the Linux kernel, the following vulnerability has been resolved: net: xfrm: unexport __init-annotated xfrm4_protocol_init() EXPORT_SYMBOL and __init is a bad combination because the .init.text s…
CVE-2022-49639 high 8.0 3y ago RHSA-2023:7077: kernel security, bug fix, and enhancement update (Important)
CVE-2022-42852 high 8.0 3y ago RHSA-2023:2834: webkit2gtk3 security and bug fix update (Important)
CVE-2022-50465 high 8.0 3y ago In the Linux kernel, the following vulnerability has been resolved: ext4: fix leaking uninitialized memory in fast-commit journal When space at the end of fast-commit journal blocks is unused, make…
CVE-2022-46700 high 8.0 3y ago RHSA-2023:2834: webkit2gtk3 security and bug fix update (Important)
CVE-2022-50100 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-49552 high 8.0 3y ago In the Linux kernel, the following vulnerability has been resolved: bpf: Fix combination of jit blinding and pointers to bpf subprogs. The combination of jit blinding and pointers to bpf subprogs c…
CVE-2022-49647 high 8.0 3y ago RHSA-2023:7077: kernel security, bug fix, and enhancement update (Important)
CVE-2022-50079 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-50050 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-50044 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-1789 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-50452 high 8.0 3y ago RHSA-2023:7077: kernel security, bug fix, and enhancement update (Important)
CVE-2022-50035 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-49434 high 8.0 3y ago In the Linux kernel, the following vulnerability has been resolved: PCI: Avoid pci_dev_lock() AB/BA deadlock with sriov_numvfs_store() The sysfs sriov_numvfs_store() path acquires the device lock b…
CVE-2022-50016 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-3628 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-36280 high 8.0 3y ago An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU component in the Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. …
CVE-2022-50007 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-49114 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-3567 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-3625 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-50405 high 8.0 3y ago RHSA-2023:7077: kernel security, bug fix, and enhancement update (Important)
CVE-2022-38023 high 8.0 3y ago RHSA-2023:0838: samba security update (Important)
CVE-2022-50425 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-4744 high 8.0 3y ago RHSA-2023:7077: kernel security, bug fix, and enhancement update (Important)
CVE-2022-4269 high 8.0 3y ago RHSA-2023:1584: kernel-rt security and bug fix update (Important)
CVE-2022-3560 high 8.0 3y ago RHSA-2023:1572: pesign security update (Important)
CVE-2022-49944 high 8.0 3y ago RHSA-2023:7077: kernel security, bug fix, and enhancement update (Important)
CVE-2022-2873 high 8.0 3y ago RHSA-2023:0854: kernel-rt security and bug fix update (Important)
CVE-2022-3564 high 8.0 3y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-4378 high 8.0 3y ago RHSA-2023:1659: kpatch-patch security update (Important)
CVE-2022-4379 high 8.0 3y ago A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial
CVE-2022-41222 high 8.0 3y ago RHSA-2023:1659: kpatch-patch security update (Important)
CVE-2022-47629 high 8.0 3y ago Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
CVE-2022-4304 high 8.0 3y ago RHSA-2023:2932: edk2 security update (Important)
CVE-2022-4450 high 8.0 3y ago RHSA-2023:2932: edk2 security update (Important)
CVE-2022-23521 high 8.0 3y ago RHSA-2023:0610: git security update (Important)
CVE-2022-41903 high 8.0 3y ago RHSA-2023:0610: git security update (Important)
CVE-2022-3077 high 8.0 3y ago A buffer overflow vulnerability was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way it handled the I2C_SMBUS_BLOCK_PROC_CALL case (via the ioctl I2C_SMBUS) with malicio…
CVE-2022-46871 high 8.0 3y ago RHSA-2023:0463: thunderbird security update (Important)
CVE-2022-46877 high 8.0 3y ago RHSA-2023:0463: thunderbird security update (Important)
CVE-2022-4139 high 8.0 3y ago RHSA-2023:0123: kpatch-patch security update (Important)
CVE-2022-46285 high 8.0 3y ago RHSA-2023:0379: libXpm security update (Important)
CVE-2022-4883 high 8.0 3y ago RHSA-2023:0379: libXpm security update (Important)
CVE-2022-2880 high 8.0 3y ago RHSA-2024:3254: container-tools:rhel8 security update (Important)
CVE-2022-44617 high 8.0 3y ago RHSA-2023:0379: libXpm security update (Important)
CVE-2022-2964 high 8.0 3y ago RHSA-2023:0123: kpatch-patch security update (Important)
CVE-2022-2959 high 8.0 3y ago A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack…
CVE-2022-41715 high 8.0 3y ago RHSA-2024:3254: container-tools:rhel8 security update (Important)
CVE-2022-44571 high 8.0 3y ago There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. This could allow an attacker to craft an input that can cau…
CVE-2022-44566 high 8.0 3y ago A denial of service vulnerability present in ActiveRecord's PostgreSQL adapter <7.0.4.1 and <6.1.7.1. When a value outside the range for a 64bit signed integer is provided to the PostgreSQL connectio…
CVE-2022-44570 high 8.0 3y ago A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount o…
CVE-2022-44572 high 8.0 3y ago A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an attacker tocraft input that can cause RFC2183 multipart boun…
CVE-2022-47318 high 8.0 3y ago ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the produc…
CVE-2022-46648 high 8.0 3y ago ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the produc…
CVE-2022-42920 high 8.0 4y ago Apache Commons BCEL vulnerable to out-of-bounds write
CVE-2022-40899 high 8.0 4y ago An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.
CVE-2022-45414 high 8.0 4y ago RHSA-2022:9074: thunderbird security update (Important)
CVE-2022-46882 high 8.0 4y ago RHSA-2022:9074: thunderbird security update (Important)
CVE-2022-46878 high 8.0 4y ago RHSA-2022:9074: thunderbird security update (Important)
CVE-2022-46880 high 8.0 4y ago RHSA-2022:9074: thunderbird security update (Important)
CVE-2022-46872 high 8.0 4y ago RHSA-2022:9074: thunderbird security update (Important)
CVE-2022-46881 high 8.0 4y ago RHSA-2022:9074: thunderbird security update (Important)
CVE-2022-46874 high 8.0 4y ago RHSA-2022:9074: thunderbird security update (Important)
CVE-2022-23520 high 8.0 4y ago rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, there is a possible XSS vulnerability with certain configurations of Rails::Html::Sani…
CVE-2022-23517 high 8.0 4y ago rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Certain configurations of rails-html-sanitizer < 1.4.4 use an inefficient regular expression that is susceptib…
CVE-2022-23516 high 8.0 4y ago Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.2.0, < 2.19.1 uses recursion for sanitizing CDATA sections, makin…
CVE-2022-23518 high 8.0 4y ago rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Versions >= 1.0.3, < 1.4.4 are vulnerable to cross-site scripting via data URIs when used in combination with …
CVE-2022-23514 high 8.0 4y ago Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptibl…
CVE-2022-23515 high 8.0 4y ago Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image…
CVE-2022-23519 high 8.0 4y ago rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. Prior to version 1.4.4, a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may…
CVE-2022-3517 high 8.0 4y ago RHSA-2023:1743: nodejs:14 security, bug fix, and enhancement update (Important)
CVE-2022-42898 high 8.0 4y ago RHSA-2022:8638: krb5 security update (Important)
CVE-2022-45060 high 8.0 4y ago RHSA-2022:8649: varnish:6 security update (Important)
CVE-2022-45416 high 8.0 4y ago RHSA-2022:8554: firefox security update (Important)
CVE-2022-45404 high 8.0 4y ago RHSA-2022:8554: firefox security update (Important)
CVE-2022-45403 high 8.0 4y ago RHSA-2022:8554: firefox security update (Important)
CVE-2022-45420 high 8.0 4y ago RHSA-2022:8554: firefox security update (Important)
CVE-2022-45410 high 8.0 4y ago RHSA-2022:8554: firefox security update (Important)
CVE-2022-45405 high 8.0 4y ago RHSA-2022:8554: firefox security update (Important)
CVE-2022-45408 high 8.0 4y ago RHSA-2022:8554: firefox security update (Important)
CVE-2022-45412 high 8.0 4y ago RHSA-2022:8554: firefox security update (Important)
CVE-2022-45409 high 8.0 4y ago RHSA-2022:8554: firefox security update (Important)
CVE-2022-45406 high 8.0 4y ago RHSA-2022:8554: firefox security update (Important)
CVE-2022-45418 high 8.0 4y ago RHSA-2022:8554: firefox security update (Important)
CVE-2022-45421 high 8.0 4y ago RHSA-2022:8554: firefox security update (Important)
CVE-2022-45411 high 8.0 4y ago RHSA-2022:8554: firefox security update (Important)
CVE-2022-42919 high 8.0 4y ago RHSA-2022:8492: python39:3.9 security update (Important)
CVE-2022-49180 high 8.0 4y ago RHSA-2023:7077: kernel security, bug fix, and enhancement update (Important)
CVE-2022-28199 high 8.0 4y ago Important: dpdk security and bug fix update
CVE-2022-50000 high 8.0 4y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-49732 high 8.0 4y ago RHSA-2023:2951: kernel security, bug fix, and enhancement update (Important)
CVE-2022-49227 high 8.0 4y ago RHSA-2022:1988: kernel security, bug fix, and enhancement update (Important)