2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1413 | HIGH | 7.5 | 0.9% | May 19, 2022 | Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0... |
| CVE-2022-29449 | MEDIUM | 5.4 | 0.5% | May 19, 2022 | Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Opal Hotel Room Booki... |
| CVE-2022-29446 | HIGH | 7.2 | 1.0% | May 19, 2022 | Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugi... |
| CVE-2022-28927 | CRITICAL | 9.8 | 33.6% | May 19, 2022 | A remote code execution (RCE) vulnerability in Subconverter v0.7.2 allows attackers to execute arbitrary code via crafte... |
| CVE-2022-1796 | HIGH | 7.8 | 1.1% | May 19, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2.4979. |
| CVE-2022-22978 | CRITICAL | 9.8 | 10.0% | May 19, 2022 | In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can ea... |
| CVE-2022-22976 | MEDIUM | 5.3 | 2.1% | May 19, 2022 | Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer... |
| CVE-2022-30018 | HIGH | 8.8 | 1.0% | May 19, 2022 | Mobotix Control Center (MxCC) through 2.5.4.5 has Insufficiently Protected Credentials, Storing Passwords in a Recoverab... |
| CVE-2022-1730 | MEDIUM | 4.6 | 0.6% | May 19, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4. |
| CVE-2022-1785 | HIGH | 7.8 | 0.5% | May 19, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977. |
| CVE-2022-1183 | HIGH | 7.5 | 4.5% | May 19, 2022 | On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerab... |
| CVE-2022-1670 | HIGH | 7.5 | 0.8% | May 19, 2022 | When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of ... |
| CVE-2022-28350 | CRITICAL | 9.8 | 1.4% | May 19, 2022 | Arm Mali GPU Kernel Driver allows improper GPU operations in Valhall r29p0 through r36p0 before r37p0 to reach a use-aft... |
| CVE-2022-28349 | CRITICAL | 9.8 | 1.2% | May 19, 2022 | Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 b... |
| CVE-2022-28348 | CRITICAL | 9.8 | 1.3% | May 19, 2022 | Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 throu... |
| CVE-2022-30138 | HIGH | 7.8 | 1.0% | May 18, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability |
| CVE-2022-29230 | MEDIUM | 5.4 | 0.7% | May 18, 2022 | Hydrogen is a React-based framework for building dynamic, Shopify-powered custom storefronts. There is a potential Cross... |
| CVE-2022-29229 | HIGH | 7.2 | 0.3% | May 18, 2022 | CaSS is a Competency and Skills System. CaSS Library, (npm:cassproject) has a missing cryptographic step when storing cr... |
| CVE-2022-1774 | MEDIUM | 6.1 | 1.1% | May 18, 2022 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7. |
| CVE-2022-30994 | HIGH | 7.5 | 0.5% | May 18, 2022 | Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows)... |
| CVE-2022-30993 | HIGH | 7.5 | 0.5% | May 18, 2022 | Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, W... |
| CVE-2022-30992 | MEDIUM | 6.1 | 0.5% | May 18, 2022 | Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux,... |
| CVE-2022-30991 | MEDIUM | 6.1 | 0.5% | May 18, 2022 | HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before bu... |
| CVE-2022-30990 | HIGH | 7.5 | 0.8% | May 18, 2022 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber ... |
| CVE-2022-30033 | HIGH | 7.5 | 1.1% | May 18, 2022 | Tenda TX9 Pro V22.03.02.10 is vulnerable to Buffer Overflow via the functtion setIPv6Status() in httpd module. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now