2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0328 | MEDIUM | 4.7 | 0.5% | Feb 28, 2022 | The Simple Membership WordPress plugin before 4.0.9 does not have CSRF check when deleting members in bulk, which could ... |
| CVE-2022-0189 | MEDIUM | 6.1 | 2.2% | Feb 28, 2022 | The WP RSS Aggregator WordPress plugin before 4.20 does not sanitise and escape the id parameter in the wprss_fetch_item... |
| CVE-2022-0150 | MEDIUM | 6.1 | 1.7% | Feb 28, 2022 | The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before... |
| CVE-2022-26159 | MEDIUM | 5.3 | 13.4% | Feb 28, 2022 | The auto-completion plugin in Ametys CMS before 4.5.0 allows a remote unauthenticated attacker to read documents such as... |
| CVE-2022-0772 | MEDIUM | 4.8 | 0.6% | Feb 27, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository librenms/librenms prior to 22.2.2. |
| CVE-2022-22908 | MEDIUM | 5.5 | 0.3% | Feb 26, 2022 | SangforCSClient.exe in Sangfor VDI Client 5.4.2.1006 allows attackers, when they are able to read process memory, to dis... |
| CVE-2022-26146 | MEDIUM | 5.4 | 0.4% | Feb 26, 2022 | Tricentis qTest before 10.4 allows stored XSS by an authenticated attacker. |
| CVE-2022-0764 | MEDIUM | 6.7 | 0.8% | Feb 26, 2022 | Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0. |
| CVE-2022-0723 | MEDIUM | 5.4 | 0.9% | Feb 26, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository microweber/microweber prior to 1.2.11. |
| CVE-2022-0763 | MEDIUM | 4.8 | 0.6% | Feb 26, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3. |
| CVE-2022-0762 | MEDIUM | 4.3 | 0.6% | Feb 26, 2022 | Incorrect Authorization in GitHub repository microweber/microweber prior to 1.3. |
| CVE-2022-24710 | MEDIUM | 5.4 | 0.7% | Feb 25, 2022 | Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutrali... |
| CVE-2022-25261 | MEDIUM | 6.1 | 0.5% | Feb 25, 2022 | JetBrains TeamCity before 2021.2.2 was vulnerable to reflected XSS. |
| CVE-2022-25259 | MEDIUM | 6.1 | 0.5% | Feb 25, 2022 | JetBrains Hub before 2021.1.14276 was vulnerable to reflected XSS. |
| CVE-2022-24347 | MEDIUM | 5.4 | 0.6% | Feb 25, 2022 | JetBrains YouTrack before 2021.4.36872 was vulnerable to stored XSS via a project icon. |
| CVE-2022-24344 | MEDIUM | 5.4 | 0.6% | Feb 25, 2022 | JetBrains YouTrack before 2021.4.31698 was vulnerable to stored XSS on the Notification templates page. |
| CVE-2022-24343 | MEDIUM | 4.3 | 0.6% | Feb 25, 2022 | In JetBrains YouTrack before 2021.4.31698, a custom logo could be set by a user who has read-only permissions. |
| CVE-2022-24339 | MEDIUM | 5.4 | 0.4% | Feb 25, 2022 | JetBrains TeamCity before 2021.2.1 was vulnerable to stored XSS. |
| CVE-2022-24338 | MEDIUM | 6.1 | 0.5% | Feb 25, 2022 | JetBrains TeamCity before 2021.2.1 was vulnerable to reflected XSS. |
| CVE-2022-24337 | MEDIUM | 6.5 | 0.7% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2, health items of pull requests were shown to users who lacked appropriate permission... |
| CVE-2022-24336 | MEDIUM | 5.3 | 0.7% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, an unauthenticated attacker can cancel running builds via an XML-RPC request to t... |
| CVE-2022-24334 | MEDIUM | 5.3 | 0.7% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, the Agent Push feature allowed selection of any private key on the server. |
| CVE-2022-24333 | MEDIUM | 6.5 | 0.7% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2, blind SSRF via an XML-RPC call was possible. |
| CVE-2022-24332 | MEDIUM | 5.3 | 0.6% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie. |
| CVE-2022-24330 | MEDIUM | 6.1 | 0.6% | Feb 25, 2022 | In JetBrains TeamCity before 2021.2.1, a redirection to an external site was possible. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now