Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2022-47945 CVE-2022-47945 CRITICAL 9.8 28.25% cvelistv5
cve-2022-47075 CVE-2022-47075 HIGH 7.5 59.41% cvelistv5
cve-2022-45933 CVE-2022-45933 CRITICAL 9.8 51.70% cvelistv5
cve-2022-43939 Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability HIGH 8.6 92.27% cvelistv5 2025-03-03
cve-2022-41412 An issue in the graphData.cgi component of perfSONAR v4.4.5 and prior allows attackers to access sensitive data and execute Server-Side Request Forgery (SSRF) attacks. HIGH 8.6 4.20% cvelistv5 2026-06-17
cve-2022-40684 Fortinet Multiple Products Authentication Bypass Vulnerability CRITICAL 9.8 99.98% cvelistv5 2022-10-11
cve-2022-4063 CVE-2022-4063 CRITICAL 9.8 9.52% cvelistv5
cve-2022-39952 A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request. CRITICAL 9.8 99.79% cvelistv5 2026-06-17
cve-2022-38627 CVE-2022-38627 CRITICAL 9.8 4.30% cvelistv5
cve-2022-36642 A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.0.0-1.4.9 allows attackers to access users credentials which makes him able to gain initial access to the control panel with high privilege because the cleartext storage of sensitive information which can be unlatched by exploiting the LFD vulnerability. CRITICAL 9.8 12.88% cvelistv5 2026-06-17
cve-2022-2958 BadgeOS < 3.7.1.3 - Subscriber+ SQLi HIGH 8.8 1.29% cvelistv5 2026-06-17
cve-2022-29081 CVE-2022-29081 HIGH N/A 83.54% cvelistv5
cve-2022-26833 CVE-2022-26833 CRITICAL 9.4 37.64% cvelistv5
cve-2022-26134 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability CRITICAL 9.8 100.00% cvelistv5 2022-06-02
cve-2022-25369 An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a logic issue when determining if the setup phases of the product can be run again. Once an attacker is authenticated as the new admin user they have added, it is possible to upload an executable file and achieve command execution. This is fixed in 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9.8, 9.10.18, 9.12.8, and 9.13.0 (and later). CRITICAL 9.8 40.01% cvelistv5 2026-06-17
cve-2022-24816 OSGeo GeoServer JAI-EXT Code Injection Vulnerability HIGH N/A 98.52% cvelistv5 2024-06-26
cve-2022-24716 SUSE CVE CVE-2022-24716 UNKNOWN N/A 89.38% cvelistv5 2025-02-16
cve-2022-23347 CVE-2022-23347 HIGH N/A 13.48% cvelistv5
cve-2022-23178 CVE-2022-23178 HIGH N/A 75.16% cvelistv5
cve-2022-22965 Spring Framework JDK 9+ Remote Code Execution Vulnerability HIGH N/A 99.64% cvelistv5 2022-04-04
cve-2022-22947 VMware Spring Cloud Gateway Code Injection Vulnerability CRITICAL 10.0 98.25% cvelistv5 2022-05-16
cve-2022-1768 CVE-2022-1768 CRITICAL 9.8 12.86% cvelistv5
cve-2022-1574 HTML2WP <= 1.0.0 - Unauthenticated Arbitrary File Upload CRITICAL 9.8 12.19% cvelistv5 2026-06-17
cve-2022-1388 F5 BIG-IP Missing Authentication Vulnerability CRITICAL N/A 99.96% cvelistv5 2022-05-10
cve-2022-1386 CVE-2022-1386 HIGH N/A 71.43% cvelistv5
cve-2022-1026 CVE-2022-1026 HIGH 8.6 14.73% cvelistv5
cve-2022-1020 CVE-2022-1020 HIGH N/A 25.94% cvelistv5
cve-2022-0952 CVE-2022-0952 HIGH N/A 11.42% cvelistv5
cve-2022-0948 CVE-2022-0948 HIGH N/A 9.88% cvelistv5
cve-2022-0867 CVE-2022-0867 HIGH N/A 13.45% cvelistv5