2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-39324LOW3.5Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user ...
CVE-2022-23552MEDIUM5.4Grafana is an open-source platform for monitoring and observability. Starting with the 8.1 branch and prior to versions ...
CVE-2022-4255MEDIUM5.3An info leak issue was identified in all versions of GitLab EE from 13.7 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6...
CVE-2022-4205HIGH7.5In Gitlab EE/CE before 15.6.1, 15.5.5 and 15.4.6 using a branch with a hexadecimal name could override an existing hash.
CVE-2022-4201MEDIUM5.3A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 all...
CVE-2022-46968MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in /index.php?page=help of Revenue Collection System v1.0 allows attac...
CVE-2022-43980MEDIUM5.4There is a stored cross-site scripting vulnerability in Pandora FMS v765 in the network maps editing functionality. An a...
CVE-2022-43979CRITICAL9.8There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that t...
CVE-2022-43978LOW3.7There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a vali...
CVE-2022-39813MEDIUM6.1Italtel NetMatch-S CI 5.2.0-20211008 allows Multiple Reflected/Stored XSS issues under NMSCIWebGui/j_security_check via ...
CVE-2022-39812HIGH7.5Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthentica...
CVE-2022-39811CRITICAL9.1Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGu...
CVE-2022-48108CRITICAL9.8D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettin...
CVE-2022-48107CRITICAL9.8D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettin...
CVE-2022-39380MEDIUM5.3Wire web-app is part of Wire communications. Versions prior to 2022-11-02 are subject to Improper Handling of Exceptiona...
CVE-2022-48118MEDIUM6.1Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Acronym parameter.
CVE-2022-48116HIGH7.2AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.in...
CVE-2022-32952Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-32472Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-4335MEDIUM4.3A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 p...
CVE-2022-4285MEDIUM5.5An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version i...
CVE-2022-4139HIGH7.8An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memor...
CVE-2022-48013MEDIUM5.4Opencats v0.9.7 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /opencats/i...
CVE-2022-48012MEDIUM6.1Opencats v0.9.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openca...
CVE-2022-48011CRITICAL9.8Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID parameter in the Import viewerr...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now