2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-24331 | CRITICAL | 9.8 | 1.1% | Feb 25, 2022 | In JetBrains TeamCity before 2021.1.4, GitLab authentication impersonation was possible. |
| CVE-2022-24330 | MEDIUM | 6.1 | 0.6% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible. |
| CVE-2022-24329 | MEDIUM | 5.3 | 2.2% | Feb 25, 2022 | In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects. |
| CVE-2022-24328 | MEDIUM | 6.5 | 0.8% | Feb 25, 2022 | In JetBrains Hub before 2021.1.13956, an unprivileged user could perform DoS. |
| CVE-2022-24327 | HIGH | 7.5 | 0.9% | Feb 25, 2022 | In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions. |
| CVE-2022-25374 | HIGH | 7.5 | 0.9% | Feb 25, 2022 | HashiCorp Terraform Enterprise v202112-1, v202112-2, v202201-1, and v202201-2 were configured to log inbound HTTP reques... |
| CVE-2022-24612 | MEDIUM | 5.4 | 0.5% | Feb 25, 2022 | An authenticated user can upload an XML file containing an XSS via the ITSM module of EyesOfNetwork 5.3.11, resulting in... |
| CVE-2022-24594 | MEDIUM | 5.3 | 0.8% | Feb 25, 2022 | In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address. |
| CVE-2022-25328 | HIGH | 7.3 | 0.2% | Feb 25, 2022 | The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege esc... |
| CVE-2022-25327 | MEDIUM | 5.5 | 0.1% | Feb 25, 2022 | The PAM module for fscrypt doesn't adequately validate fscrypt metadata files, allowing users to create malicious metada... |
| CVE-2022-25326 | MEDIUM | 5.5 | 0.1% | Feb 25, 2022 | fscrypt through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged... |
| CVE-2022-0247 | MEDIUM | 5.5 | 0.1% | Feb 25, 2022 | An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker co... |
| CVE-2022-24948 | MEDIUM | 6.1 | 2.2% | Feb 25, 2022 | A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the... |
| CVE-2022-24947 | HIGH | 8.8 | 1.1% | Feb 25, 2022 | Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki u... |
| CVE-2022-24288 | HIGH | 8.8 | 77.9% | Feb 25, 2022 | In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them... |
| CVE-2022-0746 | MEDIUM | 4.3 | 0.9% | Feb 25, 2022 | Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0. |
| CVE-2022-23835 | HIGH | 8.1 | 1.4% | Feb 25, 2022 | The Visual Voice Mail (VVM) application through 2022-02-24 for Android allows persistent access if an attacker temporari... |
| CVE-2022-23701 | MEDIUM | 5.3 | 0.7% | Feb 24, 2022 | A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO ... |
| CVE-2022-24709 | MEDIUM | 6.1 | 0.7% | Feb 24, 2022 | @awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed... |
| CVE-2022-25307 | MEDIUM | 6.1 | 1.4% | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o... |
| CVE-2022-25306 | MEDIUM | 6.1 | 1.4% | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o... |
| CVE-2022-25305 | MEDIUM | 6.1 | 81.2% | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization o... |
| CVE-2022-25149 | HIGH | 7.5 | 78.0% | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t... |
| CVE-2022-25148 | CRITICAL | 9.8 | 81.4% | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of t... |
| CVE-2022-25004 | CRITICAL | 9.8 | 1.6% | Feb 24, 2022 | Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parame... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now