2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-39324 | LOW | 3.5 | 0.8% | Jan 27, 2023 | Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user ... |
| CVE-2022-23552 | MEDIUM | 5.4 | 0.8% | Jan 27, 2023 | Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions ... |
| CVE-2022-4255 | MEDIUM | 5.3 | 0.5% | Jan 27, 2023 | An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6... |
| CVE-2022-4205 | HIGH | 7.5 | 0.6% | Jan 27, 2023 | In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash. |
| CVE-2022-4201 | MEDIUM | 5.3 | 0.5% | Jan 27, 2023 | A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 all... |
| CVE-2022-46968 | MEDIUM | 5.4 | 0.5% | Jan 27, 2023 | A stored cross-site scripting (XSS) vulnerability in /index.php?page=help of Revenue Collection System v1.0 allows attac... |
| CVE-2022-43980 | MEDIUM | 5.4 | 0.3% | Jan 27, 2023 | There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An a... |
| CVE-2022-43979 | CRITICAL | 9.8 | 0.8% | Jan 27, 2023 | There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that t... |
| CVE-2022-43978 | LOW | 3.7 | 0.3% | Jan 27, 2023 | There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a vali... |
| CVE-2022-39813 | MEDIUM | 6.1 | 0.5% | Jan 27, 2023 | Italtel NetMatch-S CI 5.2.0-20211008 allows Multiple Reflected/Stored XSS issues under NMSCIWebGui/j_security_check via ... |
| CVE-2022-39812 | HIGH | 7.5 | 1.0% | Jan 27, 2023 | Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthentica... |
| CVE-2022-39811 | CRITICAL | 9.1 | 0.8% | Jan 27, 2023 | Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGu... |
| CVE-2022-48108 | CRITICAL | 9.8 | 3.1% | Jan 27, 2023 | D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettin... |
| CVE-2022-48107 | CRITICAL | 9.8 | 3.1% | Jan 27, 2023 | D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettin... |
| CVE-2022-39380 | MEDIUM | 5.3 | 0.6% | Jan 27, 2023 | Wire web-app is part of Wire communications. Versions prior to 2022-11-02 are subject to Improper Handling of Exceptiona... |
| CVE-2022-48118 | MEDIUM | 6.1 | 0.5% | Jan 27, 2023 | Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Acronym parameter. |
| CVE-2022-48116 | HIGH | 7.2 | 1.4% | Jan 27, 2023 | AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.in... |
| CVE-2022-32952 | — | — | — | Jan 27, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-32472 | — | — | — | Jan 27, 2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-4335 | MEDIUM | 4.3 | 0.8% | Jan 27, 2023 | A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 p... |
| CVE-2022-4285 | MEDIUM | 5.5 | 0.4% | Jan 27, 2023 | An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version i... |
| CVE-2022-4139 | HIGH | 7.8 | 0.3% | Jan 27, 2023 | An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memor... |
| CVE-2022-48013 | MEDIUM | 5.4 | 0.5% | Jan 27, 2023 | Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/i... |
| CVE-2022-48012 | MEDIUM | 6.1 | 1.4% | Jan 27, 2023 | Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openca... |
| CVE-2022-48011 | CRITICAL | 9.8 | 1.1% | Jan 27, 2023 | Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerr... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now