2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24442CRITICAL9.8JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
CVE-2022-25170HIGH7.8The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an a...
CVE-2022-25019Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-38602. Reason: This candidate is a reservation d...
CVE-2022-23985HIGH7.8The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to...
CVE-2022-23921HIGH7.8Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitatio...
CVE-2022-21798CRITICAL9.8The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which ca...
CVE-2022-21209HIGH7.8The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to ...
CVE-2022-0655Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-0615HIGH7.5Use-after-free in eset_rtp kernel module used in ESET products for Linux allows potential attacker to trigger denial-of-...
CVE-2022-24347MEDIUM5.4JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon.
CVE-2022-24346HIGH7.8In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possibl...
CVE-2022-24345HIGH7.8In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project...
CVE-2022-24344MEDIUM5.4JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page.
CVE-2022-24343MEDIUM4.3In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions.
CVE-2022-24342HIGH8.8In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible.
CVE-2022-24341HIGH7.5In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the ed...
CVE-2022-24340CRITICAL9.8In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.
CVE-2022-24339MEDIUM5.4JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS.
CVE-2022-24338MEDIUM6.1JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS.
CVE-2022-24337MEDIUM6.5In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permission...
CVE-2022-24336MEDIUM5.3In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to t...
CVE-2022-24335HIGH8.1JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent r...
CVE-2022-24334MEDIUM5.3In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server.
CVE-2022-24333MEDIUM6.5In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible.
CVE-2022-24332MEDIUM5.3In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now