2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-0613MEDIUM6.5Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
CVE-2022-0612MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
CVE-2022-25242HIGH8.8In FileCloud before 21.3, file upload is not protected against Cross-Site Request Forgery (CSRF).
CVE-2022-25241HIGH8.8In FileCloud before 21.3, the CSV user import functionality is vulnerable to Cross-Site Request Forgery (CSRF).
CVE-2022-25236CRITICAL9.8xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace...
CVE-2022-25235CRITICAL9.8xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UT...
CVE-2022-0611HIGH8.8Missing Authorization in Packagist snipe/snipe-it prior to 5.3.11.
CVE-2022-23643MEDIUM6.5Sourcegraph is a code search and navigation engine. Sourcegraph versions 3.35 and 3.36 reintroduced a previously fixed s...
CVE-2022-23641MEDIUM6.5Discourse is an open source discussion platform. In versions prior to 2.8.1 in the `stable` branch, 2.9.0.beta2 in the `...
CVE-2022-24589MEDIUM6.1Burden v3.0 was discovered to contain a stored cross-site scripting (XSS) in the Add Category function. This vulnerabili...
CVE-2022-23639HIGH8.1crossbeam-utils provides atomics, synchronization primitives, scoped threads, and other utilities for concurrent program...
CVE-2022-22770CRITICAL9.8The Web Server component of TIBCO Software Inc.'s TIBCO AuditSafe contains an easily exploitable vulnerability that allo...
CVE-2022-25212HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers to connect ...
CVE-2022-25211HIGH8.8A missing permission check in Jenkins SWAMP Plugin 1.2.6 and earlier allows attackers with Overall/Read permission to co...
CVE-2022-25210MEDIUM6.5Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier uses static fields to store job configuration information, all...
CVE-2022-25209HIGH8.8Jenkins Chef Sinatra Plugin 1.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) atta...
CVE-2022-25208HIGH8.8A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission...
CVE-2022-25207HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to ha...
CVE-2022-25206HIGH8.8A missing check in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers with Overall/Read permission to connect to...
CVE-2022-25205HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins dbCharts Plugin 0.5.2 and earlier allows attackers to conne...
CVE-2022-25204MEDIUM5.4Jenkins Doktor Plugin 0.4.1 and earlier implements functionality that allows agent processes to render files on the cont...
CVE-2022-25203MEDIUM5.4Jenkins Team Views Plugin 0.9.0 and earlier does not escape team names, resulting in a stored cross-site scripting (XSS)...
CVE-2022-25202MEDIUM4.8Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name of custom promotion levels, resulting i...
CVE-2022-25201MEDIUM6.5Missing permission checks in Jenkins Checkmarx Plugin 2022.1.2 and earlier allow attackers with Overall/Read permission ...
CVE-2022-25200HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to c...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now