2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25613 | MEDIUM | 5.4 | 0.5% | Apr 4, 2022 | Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versi... |
| CVE-2022-23700 | MEDIUM | 5.5 | 0.3% | Apr 4, 2022 | A local unauthorized read access to files vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has ... |
| CVE-2022-23697 | MEDIUM | 6.1 | 0.7% | Apr 4, 2022 | A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provid... |
| CVE-2022-1233 | MEDIUM | 6.1 | 0.8% | Apr 4, 2022 | URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11. |
| CVE-2022-1190 | MEDIUM | 5.4 | 87.4% | Apr 4, 2022 | Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14... |
| CVE-2022-1189 | MEDIUM | 4.3 | 0.7% | Apr 4, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.2 before 14.7.7, all versions start... |
| CVE-2022-1188 | MEDIUM | 5.3 | 1.0% | Apr 4, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions start... |
| CVE-2022-1185 | MEDIUM | 6.5 | 1.3% | Apr 4, 2022 | A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and... |
| CVE-2022-1175 | MEDIUM | 6.1 | 82.0% | Apr 4, 2022 | Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 befor... |
| CVE-2022-1148 | MEDIUM | 6.5 | 1.1% | Apr 4, 2022 | Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8... |
| CVE-2022-1121 | MEDIUM | 5.3 | 1.0% | Apr 4, 2022 | A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8... |
| CVE-2022-1120 | MEDIUM | 6.5 | 1.0% | Apr 4, 2022 | Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and ... |
| CVE-2022-1105 | MEDIUM | 4.3 | 0.7% | Apr 4, 2022 | An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior t... |
| CVE-2022-1100 | MEDIUM | 4.3 | 0.9% | Apr 4, 2022 | A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 pr... |
| CVE-2022-1099 | MEDIUM | 4.3 | 0.9% | Apr 4, 2022 | Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.... |
| CVE-2022-0740 | MEDIUM | 4.3 | 1.0% | Apr 4, 2022 | Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting f... |
| CVE-2022-24814 | MEDIUM | 6.1 | 1.0% | Apr 4, 2022 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized Ja... |
| CVE-2022-24813 | MEDIUM | 5.3 | 1.0% | Apr 4, 2022 | CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymou... |
| CVE-2022-1170 | MEDIUM | 6.1 | 1.8% | Apr 4, 2022 | In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search... |
| CVE-2022-1169 | MEDIUM | 6.1 | 0.9% | Apr 4, 2022 | There is a XSS vulnerability in Careerfy. |
| CVE-2022-1168 | MEDIUM | 6.1 | 1.8% | Apr 4, 2022 | There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1. |
| CVE-2022-1167 | MEDIUM | 6.1 | 1.1% | Apr 4, 2022 | There are unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities in CareerUp Careerup WordPress theme befo... |
| CVE-2022-1166 | MEDIUM | 5.3 | 1.5% | Apr 4, 2022 | The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not in... |
| CVE-2022-1164 | MEDIUM | 6.1 | 0.8% | Apr 4, 2022 | The Wyzi Theme was affected by reflected XSS vulnerabilities in the business search feature |
| CVE-2022-0958 | MEDIUM | 4.8 | 0.6% | Apr 4, 2022 | The Mark Posts WordPress plugin before 2.0.1 does not escape new markers, allowing high privilege users such as admin to... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now