2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1413HIGH7.5Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0...
CVE-2022-29449MEDIUM5.4Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Opal Hotel Room Booki...
CVE-2022-29446HIGH7.2Authenticated (administrator or higher role) Local File Inclusion (LFI) vulnerability in Wow-Company's Counter Box plugi...
CVE-2022-28927CRITICAL9.8A remote code execution (RCE) vulnerability in Subconverter v0.7.2 allows attackers to execute arbitrary code via crafte...
CVE-2022-1796HIGH7.8Use After Free in GitHub repository vim/vim prior to 8.2.4979.
CVE-2022-22978CRITICAL9.8In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can ea...
CVE-2022-22976MEDIUM5.3Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer...
CVE-2022-30018HIGH8.8Mobotix Control Center (MxCC) through 2.5.4.5 has Insufficiently Protected Credentials, Storing Passwords in a Recoverab...
CVE-2022-1730MEDIUM4.6Cross-site Scripting (XSS) - Stored in GitHub repository jgraph/drawio prior to 18.0.4.
CVE-2022-1785HIGH7.8Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.
CVE-2022-1183HIGH7.5On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerab...
CVE-2022-1670HIGH7.5When generating a user invitation code in Octopus Server, the validity of this code can be set for a specific number of ...
CVE-2022-28350CRITICAL9.8Arm Mali GPU Kernel Driver allows improper GPU operations in Valhall r29p0 through r36p0 before r37p0 to reach a use-aft...
CVE-2022-28349CRITICAL9.8Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 b...
CVE-2022-28348CRITICAL9.8Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 throu...
CVE-2022-30138HIGH7.8Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-29230MEDIUM5.4Hydrogen is a React-based framework for building dynamic, Shopify-powered custom storefronts. There is a potential Cross...
CVE-2022-29229HIGH7.2CaSS is a Competency and Skills System. CaSS Library, (npm:cassproject) has a missing cryptographic step when storing cr...
CVE-2022-1774MEDIUM6.1Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository jgraph/drawio prior to 18.0.7.
CVE-2022-30994HIGH7.5Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows)...
CVE-2022-30993HIGH7.5Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, W...
CVE-2022-30992MEDIUM6.1Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux,...
CVE-2022-30991MEDIUM6.1HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before bu...
CVE-2022-30990HIGH7.5Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber ...
CVE-2022-30033HIGH7.5Tenda TX9 Pro V22.03.02.10 is vulnerable to Buffer Overflow via the functtion setIPv6Status() in httpd module.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now