2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-24331CRITICAL9.8In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible.
CVE-2022-24330MEDIUM6.1In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible.
CVE-2022-24329MEDIUM5.3In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
CVE-2022-24328MEDIUM6.5In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS.
CVE-2022-24327HIGH7.5In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
CVE-2022-25374HIGH7.5HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP reques...
CVE-2022-24612MEDIUM5.4An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in...
CVE-2022-24594MEDIUM5.3In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.
CVE-2022-25328HIGH7.3The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege esc...
CVE-2022-25327MEDIUM5.5The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metada...
CVE-2022-25326MEDIUM5.5fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged...
CVE-2022-0247MEDIUM5.5An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker co...
CVE-2022-24948MEDIUM6.1A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the...
CVE-2022-24947HIGH8.8Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki u...
CVE-2022-24288HIGH8.8In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them...
CVE-2022-0746MEDIUM4.3Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.
CVE-2022-23835HIGH8.1The Visual Voice Mail (VVM) application through 2022-02-24 for Android allows persistent access if an attacker temporari...
CVE-2022-23701MEDIUM5.3A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO ...
CVE-2022-24709MEDIUM6.1@awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed...
CVE-2022-25307MEDIUM6.1The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o...
CVE-2022-25306MEDIUM6.1The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o...
CVE-2022-25305MEDIUM6.1The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o...
CVE-2022-25149HIGH7.5The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t...
CVE-2022-25148CRITICAL9.8The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t...
CVE-2022-25004CRITICAL9.8Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parame...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now