2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36022 | MEDIUM | 5.3 | 0.4% | Nov 10, 2022 | Deeplearning4J is a suite of tools for deploying and training deep learning models using the JVM. Packages org.deeplearn... |
| CVE-2022-34666 | MEDIUM | 5.5 | 0.2% | Nov 10, 2022 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a local user wi... |
| CVE-2022-43754 | MEDIUM | 5.4 | 0.4% | Nov 10, 2022 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spacewalk/Uyuni... |
| CVE-2022-43753 | MEDIUM | 4.3 | 0.7% | Nov 10, 2022 | A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SUS... |
| CVE-2022-38121 | MEDIUM | 6.5 | 3.4% | Nov 10, 2022 | UPSMON PRO configuration file stores user password in plaintext under public user directory. A remote attacker with gene... |
| CVE-2022-38120 | MEDIUM | 6.5 | 5.6% | Nov 10, 2022 | UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerab... |
| CVE-2022-31255 | MEDIUM | 4.3 | 0.7% | Nov 10, 2022 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SU... |
| CVE-2022-42786 | MEDIUM | 5.4 | 0.4% | Nov 10, 2022 | Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute a... |
| CVE-2022-45130 | MEDIUM | 6.5 | 0.3% | Nov 10, 2022 | Plesk Obsidian allows a CSRF attack, e.g., via the /api/v2/cli/commands REST API to change an Admin password. NOTE: Obsi... |
| CVE-2022-3867 | MEDIUM | 4.3 | 0.5% | Nov 10, 2022 | HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates u... |
| CVE-2022-3866 | MEDIUM | 4.3 | 0.5% | Nov 10, 2022 | HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths... |
| CVE-2022-39398 | MEDIUM | 6.1 | 0.5% | Nov 10, 2022 | tasklists is a tasklists plugin for GLPI (Kanban). Versions prior to 2.0.3 are vulnerable to Cross-site Scripting. Cross... |
| CVE-2022-3819 | MEDIUM | 4.3 | 0.4% | Nov 10, 2022 | An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, ... |
| CVE-2022-3818 | MEDIUM | 5.3 | 0.7% | Nov 10, 2022 | An uncontrolled resource consumption issue when parsing URLs in GitLab CE/EE affecting all versions prior to 15.3.5, 15.... |
| CVE-2022-3793 | MEDIUM | 5.3 | 0.5% | Nov 10, 2022 | An improper authorization issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, ... |
| CVE-2022-3706 | MEDIUM | 4.3 | 0.5% | Nov 10, 2022 | Improper authorization in GitLab CE/EE affecting all versions from 7.14 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 ... |
| CVE-2022-3413 | MEDIUM | 4.3 | 0.5% | Nov 10, 2022 | Incorrect authorization during display of Audit Events in GitLab EE affecting all versions from 14.5 prior to 15.3.5, 15... |
| CVE-2022-3486 | MEDIUM | 6.1 | 0.7% | Nov 9, 2022 | An open redirect vulnerability in GitLab EE/CE affecting all versions from 9.3 prior to 15.3.5, 15.4 prior to 15.4.4, an... |
| CVE-2022-3483 | MEDIUM | 5.4 | 0.7% | Nov 9, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 15.3.5, all versions start... |
| CVE-2022-3280 | MEDIUM | 6.1 | 0.5% | Nov 9, 2022 | An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior ... |
| CVE-2022-3265 | MEDIUM | 5.4 | 86.3% | Nov 9, 2022 | A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 1... |
| CVE-2022-39307 | MEDIUM | 5.3 | 0.7% | Nov 9, 2022 | Grafana is an open-source platform for monitoring and observability. When using the forget password on the login page, a... |
| CVE-2022-2761 | MEDIUM | 5.3 | 0.7% | Nov 9, 2022 | An information disclosure issue in GitLab CE/EE affecting all versions from 14.4 prior to 15.3.5, 15.4 prior to 15.4.4, ... |
| CVE-2022-44590 | MEDIUM | 5.4 | 0.5% | Nov 9, 2022 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in James Lao's Simple Video Embedder plugin <= 2.2 ... |
| CVE-2022-44244 | MEDIUM | 6.6 | 1.0% | Nov 9, 2022 | An authentication bypass in Lin-CMS v0.2.1 allows attackers to escalate privileges to Super Administrator. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now