2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1188MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.1 before 14.7.7, all versions start...
CVE-2022-1185MEDIUM6.5A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7, 14.8.0 to 14.8.5, and...
CVE-2022-1175MEDIUM6.1Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 befor...
CVE-2022-1174HIGH7.5A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all versions starting from 14....
CVE-2022-1162CRITICAL9.8A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE...
CVE-2022-1148MEDIUM6.5Improper authorization in GitLab Pages included with GitLab CE/EE affecting all versions from 11.5 prior to 14.7.7, 14.8...
CVE-2022-1121MEDIUM5.3A lack of appropriate timeouts in GitLab Pages included in GitLab CE/EE all versions prior to 14.7.7, 14.8 prior to 14.8...
CVE-2022-1120MEDIUM6.5Missing filtering in an error message in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14.8.5, and ...
CVE-2022-1111LOW2.7A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 p...
CVE-2022-1105MEDIUM4.3An improper access control vulnerability in GitLab CE/EE affecting all versions from 13.11 prior to 14.7.7, 14.8 prior t...
CVE-2022-1100MEDIUM4.3A potential DOS vulnerability was discovered in GitLab CE/EE affecting all versions from 13.1 prior to 14.7.7, 14.8.0 pr...
CVE-2022-1099MEDIUM4.3Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14.7.7, 14.8 prior to 14....
CVE-2022-0740MEDIUM4.3Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting f...
CVE-2022-26572HIGH7.5Xerox ColorQube 8580 was discovered to contain an access control issue which allows attackers to print, view the status,...
CVE-2022-25569CRITICAL9.8Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthentic...
CVE-2022-24814MEDIUM6.1Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.7.0, unauthorized Ja...
CVE-2022-24813MEDIUM5.3CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Without the patch for this issue, anonymou...
CVE-2022-24801HIGH8.1Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the T...
CVE-2022-24787HIGH7.5Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. In version 0.3.1 and prior, bytestrings ca...
CVE-2022-0990CRITICAL9.1Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
CVE-2022-24785HIGH7.5Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vul...
CVE-2022-1170MEDIUM6.1In the Noo JobMonster WordPress theme before 4.5.2.9 JobMonster there is a XSS vulnerability as the input for the search...
CVE-2022-1169MEDIUM6.1There is a XSS vulnerability in Careerfy.
CVE-2022-1168MEDIUM6.1There is a Cross-Site Scripting vulnerability in the JobSearch WP JobSearch WordPress plugin before 1.5.1.
CVE-2022-1167MEDIUM6.1There are unauthenticated reflected Cross-Site Scripting (XSS) vulnerabilities in CareerUp Careerup WordPress theme befo...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now