2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29820LOW3.5In JetBrains PyCharm before 2022.1 exposure of the debugger port to the internal network was possible
CVE-2022-29819HIGH7.7In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
CVE-2022-29818HIGH7.1In JetBrains IntelliJ IDEA before 2022.1 origin checks in the internal web server were flawed
CVE-2022-29817MEDIUM6.1In JetBrains IntelliJ IDEA before 2022.1 reflected XSS via error messages in internal web server was possible
CVE-2022-29816LOW3.2In JetBrains IntelliJ IDEA before 2022.1 HTML injection into IDE messages was possible
CVE-2022-29815MEDIUM6.7In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible
CVE-2022-29814HIGH7.7In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible
CVE-2022-29813MEDIUM6.7In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
CVE-2022-29812LOW2.3In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting character...
CVE-2022-29811MEDIUM4.8In JetBrains Hub before 2022.1.14638 stored XSS via project icon was possible.
CVE-2022-1509HIGH8.8Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker...
CVE-2022-28719CRITICAL9.8Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker w...
CVE-2022-29869MEDIUM5.3cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) charact...
CVE-2022-29859CRITICAL9.8component/common/network/dhcp/dhcps.c in ambiot amb1_sdk (aka SDK for Ameba1) before 2022-03-11 mishandles data structur...
CVE-2022-24891MEDIUM6.1ESAPI (The OWASP Enterprise Security API) is a free, open source, web application security control library. Prior to ver...
CVE-2022-24736MEDIUM5.5Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load ...
CVE-2022-24735HIGH7.8Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, ...
CVE-2022-28197MEDIUM5NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_mount function, where Insufficient validat...
CVE-2022-28196MEDIUM4.6NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient va...
CVE-2022-28195MEDIUM5.7NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient val...
CVE-2022-28194MEDIUM5.6NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled...
CVE-2022-28193MEDIUM5.6NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient valida...
CVE-2022-24372MEDIUM4.6Linksys MR9600 devices before 2.0.5 allow attackers to read arbitrary files via a symbolic link to the root directory of...
CVE-2022-22315HIGH8.8IBM UrbanCode Deploy (UCD) 7.2.2.1 could allow an authenticated user with special permissions to obtain elevated privile...
CVE-2022-23822MEDIUM6.8In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now