2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-29467MEDIUM4.3Address information disclosure vulnerability in Cybozu Garoon 4.2.0 to 5.5.1 allows a remote authenticated attacker to o...
CVE-2022-28718MEDIUM4.3Operation restriction bypass vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.5.1 allow a remote authenticated atta...
CVE-2022-28713MEDIUM5.3Improper authentication vulnerability in Scheduler of Cybozu Garoon 4.10.0 to 5.5.1 allows a remote attacker to obtain s...
CVE-2022-28692MEDIUM4.3Improper input validation vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attac...
CVE-2022-27807MEDIUM4.3Improper input validation vulnerability in Link of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker t...
CVE-2022-27803MEDIUM4.3Improper input validation vulnerability in Space of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacker ...
CVE-2022-27661MEDIUM4.3Operation restriction bypass vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated att...
CVE-2022-27627MEDIUM6.1Cross-site scripting vulnerability in Organization's Information of Cybozu Garoon 4.10.2 to 5.5.1 allows a remote attack...
CVE-2022-26368MEDIUM5.4Browse restriction bypass and operation restriction bypass vulnerability in Cabinet of Cybozu Garoon 4.0.0 to 5.5.1 allo...
CVE-2022-26054MEDIUM4.3Operation restriction bypass vulnerability in Link of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attacke...
CVE-2022-26051MEDIUM4.3Operation restriction bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.5.1 allows a remote authenticated attac...
CVE-2022-2290MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository zadam/trilium prior to 0.52.4, 0.53.1-beta.
CVE-2022-34912MEDIUM6.1An issue was discovered in MediaWiki before 1.37.3 and 1.38.x before 1.38.1. The contributions-title, used on Special:Co...
CVE-2022-34911MEDIUM6.1An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.37.3, and 1.38.x before 1.38.1. XSS can o...
CVE-2022-34903MEDIUM6.5GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyrin...
CVE-2022-32325MEDIUM6.5JPEGOPTIM v1.4.7 was discovered to contain a segmentation violation which is caused by a READ memory access at jpegoptim...
CVE-2022-25896MEDIUM4.8This affects the package passport before 0.6.0. When a user logs in or logs out, the session is regenerated instead of b...
CVE-2022-25876MEDIUM5.5The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to...
CVE-2022-22373MEDIUM5.4An improper validation vulnerability in IBM InfoSphere Information Server 11.7 Pack for SAP Apps and BW Packs may lead t...
CVE-2022-22367MEDIUM5.5IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive database information to a l...
CVE-2022-22366MEDIUM4.4IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 stores user credentials in plain clear text which ca...
CVE-2022-1954MEDIUM5.3A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5,...
CVE-2022-0167MEDIUM6.1An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.4.5, all versions starting fr...
CVE-2022-31113MEDIUM6.1Canarytokens is an open source tool which helps track activity and actions on your network. A Cross-Site Scripting vulne...
CVE-2022-2270MEDIUM5.3An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting f...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now