2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24442 | CRITICAL | 9.8 | 3.6% | Feb 25, 2022 | JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. |
| CVE-2022-25170 | HIGH | 7.8 | 0.9% | Feb 25, 2022 | The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an a... |
| CVE-2022-25019 | — | — | — | Feb 25, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-38602. Reason: This candidate is a reservation d... |
| CVE-2022-23985 | HIGH | 7.8 | 1.8% | Feb 25, 2022 | The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to... |
| CVE-2022-23921 | HIGH | 7.8 | 0.2% | Feb 25, 2022 | Exploitation of this vulnerability may result in local privilege escalation and code execution. GE maintains exploitatio... |
| CVE-2022-21798 | CRITICAL | 9.8 | 0.6% | Feb 25, 2022 | The affected product is vulnerable due to cleartext transmission of credentials seen in the CIMPLICITY network, which ca... |
| CVE-2022-21209 | HIGH | 7.8 | 1.8% | Feb 25, 2022 | The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to ... |
| CVE-2022-0655 | — | — | — | Feb 25, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-0615 | HIGH | 7.5 | 0.8% | Feb 25, 2022 | Use-after-free in eset_rtp kernel module used in ESET products for Linux allows potential attacker to trigger denial-of-... |
| CVE-2022-24347 | MEDIUM | 5.4 | 0.6% | Feb 25, 2022 | JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon. |
| CVE-2022-24346 | HIGH | 7.8 | 0.4% | Feb 25, 2022 | In JetBrains IntelliJ IDEA before 2021.3.1, local code execution via RLO (Right-to-Left Override) characters was possibl... |
| CVE-2022-24345 | HIGH | 7.8 | 0.4% | Feb 25, 2022 | In JetBrains IntelliJ IDEA before 2021.2.4, local code execution (without permission from a user) upon opening a project... |
| CVE-2022-24344 | MEDIUM | 5.4 | 0.6% | Feb 25, 2022 | JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page. |
| CVE-2022-24343 | MEDIUM | 4.3 | 0.6% | Feb 25, 2022 | In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions. |
| CVE-2022-24342 | HIGH | 8.8 | 3.2% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, URL injection leading to CSRF was possible. |
| CVE-2022-24341 | HIGH | 7.5 | 0.7% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the ed... |
| CVE-2022-24340 | CRITICAL | 9.8 | 1.0% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible. |
| CVE-2022-24339 | MEDIUM | 5.4 | 0.4% | Feb 25, 2022 | JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS. |
| CVE-2022-24338 | MEDIUM | 6.1 | 0.5% | Feb 25, 2022 | JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS. |
| CVE-2022-24337 | MEDIUM | 6.5 | 0.7% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permission... |
| CVE-2022-24336 | MEDIUM | 5.3 | 0.7% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to t... |
| CVE-2022-24335 | HIGH | 8.1 | 0.7% | Feb 25, 2022 | JetBrains TeamCity before 2021.2 was vulnerable to a Time-of-check/Time-of-use (TOCTOU) race-condition attack in agent r... |
| CVE-2022-24334 | MEDIUM | 5.3 | 0.7% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server. |
| CVE-2022-24333 | MEDIUM | 6.5 | 0.7% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible. |
| CVE-2022-24332 | MEDIUM | 5.3 | 0.6% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now