2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0210MEDIUM4.8The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the cat...
CVE-2022-0172MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.3. Under certain conditions it was ...
CVE-2022-0154HIGH8An issue has been discovered in GitLab affecting all versions starting from 7.7 before 14.4.5, all versions starting fro...
CVE-2022-0152MEDIUM6.5An issue has been discovered in GitLab affecting all versions starting from 13.10 before 14.4.5, all versions starting f...
CVE-2022-0151MEDIUM4.9An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.4.5, all versions starting f...
CVE-2022-0125MEDIUM4.3An issue has been discovered in GitLab affecting all versions starting from 12.0 before 14.4.5, all versions starting fr...
CVE-2022-0124MEDIUM4.3An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 an...
CVE-2022-0093MEDIUM4.3An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 an...
CVE-2022-0090MEDIUM6.5An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 an...
CVE-2022-23307HIGH8.8CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw wa...
CVE-2022-23305CRITICAL9.8By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be ...
CVE-2022-23302HIGH8.8JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write acce...
CVE-2022-0263HIGH7.8Unrestricted Upload of File with Dangerous Type in Packagist pimcore/pimcore prior to 10.2.7.
CVE-2022-0262MEDIUM6.1Cross-site Scripting (XSS) - Stored in Packagist pimcore/pimcore prior to 10.2.7.
CVE-2022-0261HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
CVE-2022-0260MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.2.7.
CVE-2022-0245MEDIUM4.3Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.
CVE-2022-22703MEDIUM5.5In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the...
CVE-2022-0242HIGH7.2Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.
CVE-2022-0258HIGH8.8pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
CVE-2022-0257MEDIUM5.4pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-0256MEDIUM5.4pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-0253MEDIUM5.4livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-0240HIGH7.5mruby is vulnerable to NULL Pointer Dereference
CVE-2022-0184MEDIUM4.3Insufficiently protected credentials vulnerability in 'TEPRA' PRO SR5900P Ver.1.080 and earlier and 'TEPRA' PRO SR-R7900...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now