2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0210 | MEDIUM | 4.8 | 4.4% | Jan 18, 2022 | The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the cat... |
| CVE-2022-0172 | MEDIUM | 6.5 | 0.8% | Jan 18, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was ... |
| CVE-2022-0154 | HIGH | 8 | 0.5% | Jan 18, 2022 | An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting fro... |
| CVE-2022-0152 | MEDIUM | 6.5 | 1.1% | Jan 18, 2022 | An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting f... |
| CVE-2022-0151 | MEDIUM | 4.9 | 1.1% | Jan 18, 2022 | An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting f... |
| CVE-2022-0125 | MEDIUM | 4.3 | 0.9% | Jan 18, 2022 | An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting fr... |
| CVE-2022-0124 | MEDIUM | 4.3 | 1.0% | Jan 18, 2022 | An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 an... |
| CVE-2022-0093 | MEDIUM | 4.3 | 0.9% | Jan 18, 2022 | An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 an... |
| CVE-2022-0090 | MEDIUM | 6.5 | 1.3% | Jan 18, 2022 | An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 an... |
| CVE-2022-23307 | HIGH | 8.8 | 52.5% | Jan 18, 2022 | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw wa... |
| CVE-2022-23305 | CRITICAL | 9.8 | 66.5% | Jan 18, 2022 | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be ... |
| CVE-2022-23302 | HIGH | 8.8 | 61.8% | Jan 18, 2022 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write acce... |
| CVE-2022-0263 | HIGH | 7.8 | 1.1% | Jan 18, 2022 | Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7. |
| CVE-2022-0262 | MEDIUM | 6.1 | 1.5% | Jan 18, 2022 | Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7. |
| CVE-2022-0261 | HIGH | 7.8 | 1.7% | Jan 18, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-0260 | MEDIUM | 5.4 | 0.7% | Jan 18, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.7. |
| CVE-2022-0245 | MEDIUM | 4.3 | 0.4% | Jan 18, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0. |
| CVE-2022-22703 | MEDIUM | 5.5 | 0.2% | Jan 17, 2022 | In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the... |
| CVE-2022-0242 | HIGH | 7.2 | 1.4% | Jan 17, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0. |
| CVE-2022-0258 | HIGH | 8.8 | 1.6% | Jan 17, 2022 | pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command |
| CVE-2022-0257 | MEDIUM | 5.4 | 1.5% | Jan 17, 2022 | pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2022-0256 | MEDIUM | 5.4 | 0.6% | Jan 17, 2022 | pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2022-0253 | MEDIUM | 5.4 | 0.8% | Jan 17, 2022 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2022-0240 | HIGH | 7.5 | 1.0% | Jan 17, 2022 | mruby is vulnerable to NULL Pointer Dereference |
| CVE-2022-0184 | MEDIUM | 4.3 | 0.3% | Jan 17, 2022 | Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now