2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-27658HIGH7.5Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could ...
CVE-2022-26980MEDIUM6.1Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO.
CVE-2022-1056MEDIUM5.5Out-of-bounds Read error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff f...
CVE-2022-0751HIGH8.8Inaccurate display of Snippet files containing special characters in all versions of GitLab CE/EE allows an attacker to ...
CVE-2022-0738HIGH7.5An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting fr...
CVE-2022-0735CRITICAL9.8An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions star...
CVE-2022-0549MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions before 14.3.6, all versions starting from 14.4 befor...
CVE-2022-0488MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigg...
CVE-2022-0427HIGH8.8Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows a...
CVE-2022-0371MEDIUM4.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.4 before 14.5.4, all versions start...
CVE-2022-0344MEDIUM4.3An issue has been discovered in GitLab affecting all versions starting from 10.0 before 14.5.4, all versions starting fr...
CVE-2022-0283MEDIUM6.1An issue has been discovered affecting GitLab versions prior to 13.5. An open redirect vulnerability was fixed in GitLab...
CVE-2022-0249CRITICAL9.1A vulnerability was discovered in GitLab starting with version 12. GitLab was vulnerable to a blind SSRF attack since re...
CVE-2022-0136HIGH8.1A vulnerability was discovered in GitLab versions 10.5 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7.1. GitLab was vulnera...
CVE-2022-0123MEDIUM6.8An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 an...
CVE-2022-0846CRITICAL9.8The SpeakOut! Email Petitions WordPress plugin before 2.14.15.1 does not sanitise and escape the id parameter before usi...
CVE-2022-0833MEDIUM4.3The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of its action as well as r...
CVE-2022-0818MEDIUM6.1The WooCommerce Affiliate Plugin WordPress plugin before 4.16.4.5 does not have authorization and CSRF checks on a speci...
CVE-2022-0787CRITICAL9.8The Limit Login Attempts (Spam Protection) WordPress plugin before 5.1 does not sanitise and escape some parameters befo...
CVE-2022-0784CRITICAL9.8The Title Experiments Free WordPress plugin before 9.0.1 does not sanitise and escape the id parameter before using it i...
CVE-2022-0770HIGH8.8The Translate WordPress with GTranslate WordPress plugin before 2.9.9 does not have CSRF check in some files, and write ...
CVE-2022-0720MEDIUM5.4The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing appointments, allowing any cu...
CVE-2022-0680MEDIUM6.1The Plezi WordPress plugin before 1.0.3 has a REST endpoint allowing unauthenticated users to update the plz_configurati...
CVE-2022-0679CRITICAL9.8The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is...
CVE-2022-0647MEDIUM6.1The Bulk Creator WordPress plugin through 1.0.1 does not sanitize and escape the post_type parameter before outputting i...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now