2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2228 | MEDIUM | 6.5 | 0.6% | Jul 1, 2022 | Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prio... |
| CVE-2022-1999 | MEDIUM | 5.3 | 0.6% | Jul 1, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, an... |
| CVE-2022-1963 | MEDIUM | 5.3 | 1.1% | Jul 1, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions star... |
| CVE-2022-2281 | MEDIUM | 5.3 | 0.7% | Jul 1, 2022 | An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15... |
| CVE-2022-2254 | MEDIUM | 4.8 | 0.4% | Jul 1, 2022 | A user with administrative privileges in Distributed Data Systems WebHMI 4.1.1.7662 can store a script that could impact... |
| CVE-2022-2250 | MEDIUM | 6.1 | 1.2% | Jul 1, 2022 | An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, ... |
| CVE-2022-2244 | MEDIUM | 4.3 | 0.7% | Jul 1, 2022 | An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to... |
| CVE-2022-2243 | MEDIUM | 4.3 | 0.6% | Jul 1, 2022 | An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4,... |
| CVE-2022-2235 | MEDIUM | 5.4 | 0.7% | Jul 1, 2022 | Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 ... |
| CVE-2022-2230 | MEDIUM | 4.8 | 56.2% | Jul 1, 2022 | A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.... |
| CVE-2022-2227 | MEDIUM | 4.3 | 0.6% | Jul 1, 2022 | Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15... |
| CVE-2022-1983 | MEDIUM | 4.3 | 0.5% | Jul 1, 2022 | Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 p... |
| CVE-2022-34894 | MEDIUM | 5.3 | 0.5% | Jul 1, 2022 | In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services |
| CVE-2022-2280 | MEDIUM | 5.4 | 0.5% | Jul 1, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19. |
| CVE-2022-2279 | MEDIUM | 5.5 | 0.5% | Jul 1, 2022 | NULL Pointer Dereference in GitHub repository bfabiszewski/libmobi prior to 0.11. |
| CVE-2022-32988 | MEDIUM | 5.4 | 0.5% | Jul 1, 2022 | Cross Site Scripting (XSS) vulnerability in router Asus DSL-N14U-B1 1.1.2.3_805 via the "*list" parameters (e.g. filter_... |
| CVE-2022-23725 | MEDIUM | 5.5 | 0.2% | Jun 30, 2022 | PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensit... |
| CVE-2022-23719 | MEDIUM | 6.4 | 0.3% | Jun 30, 2022 | PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security... |
| CVE-2022-23717 | MEDIUM | 5.5 | 0.2% | Jun 30, 2022 | PingID Windows Login prior to 2.8 is vulnerable to a denial of service condition on local machines when combined with us... |
| CVE-2022-34818 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier does not perform permission checks in several views and HTTP end... |
| CVE-2022-34817 | MEDIUM | 4.3 | 0.4% | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier allows atta... |
| CVE-2022-34816 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenki... |
| CVE-2022-34815 | MEDIUM | 4.3 | 0.4% | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier allows at... |
| CVE-2022-34814 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier does not correctly perform a permission check in an HTTP endpo... |
| CVE-2022-34813 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now