2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1188 | MEDIUM | 5.3 | 1.0% | Apr 4, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions start... |
| CVE-2022-1185 | MEDIUM | 6.5 | 1.3% | Apr 4, 2022 | A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and... |
| CVE-2022-1175 | MEDIUM | 6.1 | 82.0% | Apr 4, 2022 | Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 befor... |
| CVE-2022-1174 | HIGH | 7.5 | 1.4% | Apr 4, 2022 | A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14.... |
| CVE-2022-1162 | CRITICAL | 9.8 | 76.2% | Apr 4, 2022 | A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE... |
| CVE-2022-1148 | MEDIUM | 6.5 | 1.1% | Apr 4, 2022 | Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8... |
| CVE-2022-1121 | MEDIUM | 5.3 | 1.0% | Apr 4, 2022 | A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8... |
| CVE-2022-1120 | MEDIUM | 6.5 | 1.0% | Apr 4, 2022 | Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and ... |
| CVE-2022-1111 | LOW | 2.7 | 0.6% | Apr 4, 2022 | A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 p... |
| CVE-2022-1105 | MEDIUM | 4.3 | 0.7% | Apr 4, 2022 | An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior t... |
| CVE-2022-1100 | MEDIUM | 4.3 | 0.9% | Apr 4, 2022 | A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 pr... |
| CVE-2022-1099 | MEDIUM | 4.3 | 0.9% | Apr 4, 2022 | Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.... |
| CVE-2022-0740 | MEDIUM | 4.3 | 1.0% | Apr 4, 2022 | Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting f... |
| CVE-2022-26572 | HIGH | 7.5 | 0.9% | Apr 4, 2022 | Xerox ColorQube 8580 was discovered to contain an access control issue which allows attackers to print, view the status,... |
| CVE-2022-25569 | CRITICAL | 9.8 | 1.1% | Apr 4, 2022 | Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthentic... |
| CVE-2022-24814 | MEDIUM | 6.1 | 1.0% | Apr 4, 2022 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized Ja... |
| CVE-2022-24813 | MEDIUM | 5.3 | 1.0% | Apr 4, 2022 | CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymou... |
| CVE-2022-24801 | HIGH | 8.1 | 2.8% | Apr 4, 2022 | Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the T... |
| CVE-2022-24787 | HIGH | 7.5 | 1.0% | Apr 4, 2022 | Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. In version 0.3.1 and prior, bytestrings ca... |
| CVE-2022-0990 | CRITICAL | 9.1 | 1.3% | Apr 4, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. |
| CVE-2022-24785 | HIGH | 7.5 | 5.7% | Apr 4, 2022 | Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vul... |
| CVE-2022-1170 | MEDIUM | 6.1 | 1.8% | Apr 4, 2022 | In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search... |
| CVE-2022-1169 | MEDIUM | 6.1 | 0.9% | Apr 4, 2022 | There is a XSS vulnerability in Careerfy. |
| CVE-2022-1168 | MEDIUM | 6.1 | 1.8% | Apr 4, 2022 | There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1. |
| CVE-2022-1167 | MEDIUM | 6.1 | 1.1% | Apr 4, 2022 | There are unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities in CareerUp Careerup WordPress theme befo... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now