Known Exploited Vulnerabilities (KEV)
| ID | Title | Severity | CVSS | EPSS | Source | Updated |
|---|---|---|---|---|---|---|
| cve-2022-26134 | Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability | CRITICAL | 9.8 | 100.00% | cvelistv5 | 2022-06-02 |
| cve-2022-2586 | Linux Kernel Use-After-Free Vulnerability | HIGH | N/A | 10.20% | cvelistv5 | 2024-06-26 |
| cve-2022-25487 | CVE-2022-25487 | HIGH | N/A | 53.84% | cvelistv5 | |
| cve-2022-25486 | CVE-2022-25486 | HIGH | N/A | 9.97% | cvelistv5 | |
| cve-2022-25485 | CVE-2022-25485 | HIGH | N/A | 7.93% | cvelistv5 | |
| cve-2022-25369 | An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a logic issue when determining if the setup phases of the product can be run again. Once an attacker is authenticated as the new admin user they have added, it is possible to upload an executable file and achieve command execution. This is fixed in 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9.8, 9.10.18, 9.12.8, and 9.13.0 (and later). | CRITICAL | 9.8 | 40.01% | cvelistv5 | 2026-06-17 |
| cve-2022-25322 | CVE-2022-25322 | HIGH | N/A | 8.35% | cvelistv5 | |
| cve-2022-25237 | CVE-2022-25237 | HIGH | N/A | 56.45% | cvelistv5 | |
| cve-2022-25075 | CVE-2022-25075 | HIGH | N/A | 56.25% | cvelistv5 | |
| cve-2022-24990 | TerraMaster OS Remote Command Execution Vulnerability | CRITICAL | N/A | 83.04% | cvelistv5 | 2023-02-10 |
| cve-2022-2488 | WAVLINK WN535K2/WN535K3 touchlist_sync.cgi os command injection | HIGH | 8.0 | 33.76% | cvelistv5 | 2026-06-17 |
| cve-2022-2487 | CVE-2022-2487 | HIGH | 8.0 | 79.51% | cvelistv5 | |
| cve-2022-2486 | WAVLINK WN535K2/WN535K3 os command injection | HIGH | 8.0 | 30.52% | cvelistv5 | 2026-06-17 |
| cve-2022-24816 | OSGeo GeoServer JAI-EXT Code Injection Vulnerability | HIGH | N/A | 99.91% | cvelistv5 | 2024-06-26 |
| cve-2022-24716 | SUSE CVE CVE-2022-24716 | UNKNOWN | N/A | 89.38% | cvelistv5 | 2025-02-16 |
| cve-2022-24706 | SUSE CVE CVE-2022-24706 | UNKNOWN | N/A | 92.51% | cvelistv5 | 2025-04-25 |
| cve-2022-24682 | Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability | MEDIUM | 6.1 | 30.93% | cvelistv5 | 2022-02-25 |
| cve-2022-24521 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | HIGH | 7.8 | 7.13% | cvelistv5 | 2026-06-17 |
| cve-2022-24288 | Airflow: RCE in example DAGs | CRITICAL | 9.9 | 77.88% | cvelistv5 | 2025-11-21 |
| cve-2022-24260 | CVE-2022-24260 | HIGH | N/A | 49.99% | cvelistv5 | |
| cve-2022-2414 | pki-core: access to external entities when parsing XML can lead to XXE | HIGH | 7.5 | 85.97% | cvelistv5 | 2025-11-21 |
| cve-2022-24112 | Apache APISIX Authentication Bypass Vulnerability | HIGH | N/A | 96.07% | cvelistv5 | 2022-08-25 |
| cve-2022-24086 | Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability | CRITICAL | 9.8 | 99.20% | cvelistv5 | 2022-02-15 |
| cve-2022-23961 | CVE-2022-23961 | MEDIUM | 6.1 | 0.20% | cvelistv5 | |
| cve-2022-23900 | CVE-2022-23900 | HIGH | N/A | 3.52% | cvelistv5 | |
| cve-2022-2376 | CVE-2022-2376 | HIGH | N/A | 1.84% | cvelistv5 | |
| cve-2022-23748 | Dante Discovery Process Control Vulnerability | HIGH | 7.8 | 9.09% | cvelistv5 | 2025-02-06 |
| cve-2022-23347 | CVE-2022-23347 | HIGH | N/A | 13.48% | cvelistv5 | |
| cve-2022-23227 | NUUO NVRmini2 Devices Missing Authentication Vulnerability | HIGH | N/A | 48.50% | cvelistv5 | 2024-12-18 |
| cve-2022-23178 | CVE-2022-23178 | HIGH | N/A | 75.16% | cvelistv5 |