2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27658 | HIGH | 7.5 | 0.9% | Mar 28, 2022 | Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could ... |
| CVE-2022-26980 | MEDIUM | 6.1 | 1.1% | Mar 28, 2022 | Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO. |
| CVE-2022-1056 | MEDIUM | 5.5 | 1.1% | Mar 28, 2022 | Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff f... |
| CVE-2022-0751 | HIGH | 8.8 | 1.4% | Mar 28, 2022 | Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to ... |
| CVE-2022-0738 | HIGH | 7.5 | 0.8% | Mar 28, 2022 | An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting fr... |
| CVE-2022-0735 | CRITICAL | 9.8 | 13.2% | Mar 28, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions star... |
| CVE-2022-0549 | MEDIUM | 6.5 | 0.9% | Mar 28, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 befor... |
| CVE-2022-0488 | MEDIUM | 4.3 | 0.7% | Mar 28, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigg... |
| CVE-2022-0427 | HIGH | 8.8 | 0.8% | Mar 28, 2022 | Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows a... |
| CVE-2022-0371 | MEDIUM | 4.3 | 0.9% | Mar 28, 2022 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions start... |
| CVE-2022-0344 | MEDIUM | 4.3 | 1.1% | Mar 28, 2022 | An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting fr... |
| CVE-2022-0283 | MEDIUM | 6.1 | 0.7% | Mar 28, 2022 | An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab... |
| CVE-2022-0249 | CRITICAL | 9.1 | 1.1% | Mar 28, 2022 | A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since re... |
| CVE-2022-0136 | HIGH | 8.1 | 0.8% | Mar 28, 2022 | A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnera... |
| CVE-2022-0123 | MEDIUM | 6.8 | 0.4% | Mar 28, 2022 | An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 an... |
| CVE-2022-0846 | CRITICAL | 9.8 | 8.8% | Mar 28, 2022 | The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before usi... |
| CVE-2022-0833 | MEDIUM | 4.3 | 0.5% | Mar 28, 2022 | The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as r... |
| CVE-2022-0818 | MEDIUM | 6.1 | 0.9% | Mar 28, 2022 | The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a speci... |
| CVE-2022-0787 | CRITICAL | 9.8 | 8.9% | Mar 28, 2022 | The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters befo... |
| CVE-2022-0784 | CRITICAL | 9.8 | 10.4% | Mar 28, 2022 | The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it i... |
| CVE-2022-0770 | HIGH | 8.8 | 0.6% | Mar 28, 2022 | The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write ... |
| CVE-2022-0720 | MEDIUM | 5.4 | 0.6% | Mar 28, 2022 | The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any cu... |
| CVE-2022-0680 | MEDIUM | 6.1 | 0.9% | Mar 28, 2022 | The Plezi WordPress plugin before 1.0.3 has a REST endpoint allowing unauthenticated users to update the plz_configurati... |
| CVE-2022-0679 | CRITICAL | 9.8 | 47.8% | Mar 28, 2022 | The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is... |
| CVE-2022-0647 | MEDIUM | 6.1 | 0.8% | Mar 28, 2022 | The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting i... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now