2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0425HIGH7.6A DNS rebinding vulnerability in the Irker IRC Gateway integration in all versions of GitLab CE/EE since version 7.9 all...
CVE-2022-0390MEDIUM4.3Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1 allowed for project ...
CVE-2022-0373MEDIUM4.3Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7.1 allows project non-m...
CVE-2022-27306Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-26565MEDIUM4.8A cross-site scripting (XSS) vulnerability in Totaljs all versions before commit 95f54a5commit, allows attackers to exec...
CVE-2022-26562CRITICAL9.8An issue in provider/libserver/ECKrbAuth.cpp of Kopano Core <= v11.0.2.51 contains an issue which allows attackers to au...
CVE-2022-24426HIGH7.8Dell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerabili...
CVE-2022-24066CRITICAL9.8The package simple-git before 3.5.0 are vulnerable to Command Injection due to an incomplete fix of [CVE-2022-24433](htt...
CVE-2022-23158MEDIUM4.4Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A local authenticated user...
CVE-2022-23157MEDIUM4.4Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A authenticated malicious ...
CVE-2022-23156MEDIUM6.7Wyse Device Agent version 14.6.1.4 and below contain an Improper Authentication vulnerability. A malicious user could po...
CVE-2022-23155HIGH7.2Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious use...
CVE-2022-1207MEDIUM6.6Out-of-bounds read in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability allows attackers to read se...
CVE-2022-24440CRITICAL9.8The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git a...
CVE-2022-21223CRITICAL9.8The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When callin...
CVE-2022-22404MEDIUM6.5IBM App Connect Enterprise Certified Container Dashboard UI (IBM App Connect Enterprise Certified Container 1.5, 2.0, 2....
CVE-2022-22332HIGH7.5IBM Sterling Partner Engagement Manager 6.2.0 could allow an attacker to impersonate another user due to missing revocat...
CVE-2022-22331HIGH7.1IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to obtain sensitive information...
CVE-2022-22328MEDIUM6.2IBM SterlingPartner Engagement Manager 6.2.0 could allow a malicious user to elevate their privileges and perform uninte...
CVE-2022-22327HIGH7.5IBM UrbanCode Deploy (UCD) 7.0.5, 7.1.0, 7.1.1, and 7.1.2 uses weaker than expected cryptographic algorithms that could ...
CVE-2022-21235CRITICAL9.8The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg...
CVE-2022-24181MEDIUM6.1Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to...
CVE-2022-21947HIGH8.8A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to...
CVE-2022-25017HIGH8.8Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field.
CVE-2022-24803CRITICAL9.8Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension. Versions prior to 0.4...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now