2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-2228MEDIUM6.5Information exposure in GitLab EE affecting all versions from 12.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prio...
CVE-2022-1999MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 prior to 14.10.5, 15.0 prior to 15.0.4, an...
CVE-2022-1963MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.4 before 14.10.5, all versions star...
CVE-2022-2281MEDIUM5.3An information disclosure vulnerability in GitLab EE affecting all versions from 12.5 prior to 14.10.5, 15.0 prior to 15...
CVE-2022-2254MEDIUM4.8A user with administrative privileges in Distributed Data Systems WebHMI 4.1.1.7662 can store a script that could impact...
CVE-2022-2250MEDIUM6.1An open redirect vulnerability in GitLab EE/CE affecting all versions from 11.1 prior to 14.10.5, 15.0 prior to 15.0.4, ...
CVE-2022-2244MEDIUM4.3An improper authorization vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to...
CVE-2022-2243MEDIUM4.3An access control vulnerability in GitLab EE/CE affecting all versions from 14.8 prior to 14.10.5, 15.0 prior to 15.0.4,...
CVE-2022-2235MEDIUM5.4Insufficient sanitization in GitLab EE's external issue tracker affecting all versions from 14.5 prior to 14.10.5, 15.0 ...
CVE-2022-2230MEDIUM4.8A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14....
CVE-2022-2227MEDIUM4.3Improper access control in the runner jobs API in GitLab CE/EE affecting all versions prior to 14.10.5, 15.0 prior to 15...
CVE-2022-1983MEDIUM4.3Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 p...
CVE-2022-34894MEDIUM5.3In JetBrains Hub before 2022.2.14799, insufficient access control allowed the hijacking of untrusted services
CVE-2022-2280MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.2.19.
CVE-2022-2279MEDIUM5.5NULL Pointer Dereference in GitHub repository bfabiszewski/libmobi prior to 0.11.
CVE-2022-32988MEDIUM5.4Cross Site Scripting (XSS) vulnerability in router Asus DSL-N14U-B1 1.1.2.3_805 via the "*list" parameters (e.g. filter_...
CVE-2022-23725MEDIUM5.5PingID Windows Login prior to 2.8 does not properly set permissions on the Windows Registry entries used to store sensit...
CVE-2022-23719MEDIUM6.4PingID Windows Login prior to 2.8 does not authenticate communication with a local Java service used to capture security...
CVE-2022-23717MEDIUM5.5PingID Windows Login prior to 2.8 is vulnerable to a denial of service condition on local machines when combined with us...
CVE-2022-34818MEDIUM4.3Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier does not perform permission checks in several views and HTTP end...
CVE-2022-34817MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier allows atta...
CVE-2022-34816MEDIUM6.5Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenki...
CVE-2022-34815MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier allows at...
CVE-2022-34814MEDIUM4.3Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier does not correctly perform a permission check in an HTTP endpo...
CVE-2022-34813MEDIUM4.3A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now