2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25174HIGH8.8Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for di...
CVE-2022-25173HIGH8.8Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when...
CVE-2022-24590MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to ex...
CVE-2022-24588MEDIUM5.4Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function.
CVE-2022-24587MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attacke...
CVE-2022-24585MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attac...
CVE-2022-24226HIGH7.5Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function ...
CVE-2022-23604HIGH7.2x26-Cogs is a repository of cogs made by Twentysix for the Red Discord bot. Among these cogs is the Defender cog, a tool...
CVE-2022-21698HIGH7.5client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golan...
CVE-2022-24684MEDIUM6.5HashiCorp Nomad and Nomad Enterprise 0.9.0 through 1.0.16, 1.1.11, and 1.2.5 allow operators with job-submit capabilitie...
CVE-2022-24227MEDIUM6.1A cross-site scripting (XSS) vulnerability in BoltWire v7.10 and v 8.00 allows attackers to execute arbitrary web script...
CVE-2022-24586MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows at...
CVE-2022-0597MEDIUM6.1Open Redirect in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0596MEDIUM4.3Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-23384HIGH8.8YzmCMS v6.3 is affected by Cross Site Request Forgery (CSRF) in /admin.add
CVE-2022-23317HIGH7.5CobaltStrike <=4.5 HTTP(S) listener does not determine whether the request URL begins with "/", and attackers can obtain...
CVE-2022-0589MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0.
CVE-2022-0588MEDIUM6.5Missing Authorization in Packagist librenms/librenms prior to 22.2.0.
CVE-2022-0587MEDIUM6.5Improper Authorization in Packagist librenms/librenms prior to 22.2.0.
CVE-2022-21818MEDIUM5.4NVIDIA License System contains a vulnerability in the installation scripts for the DLS virtual appliance, where a user o...
CVE-2022-0580HIGH8.8Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.
CVE-2022-25139CRITICAL9.8njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled.
CVE-2022-24705CRITICAL9.8The rad_packet_recv function in radius/packet.c suffers from a memcpy buffer overflow, resulting in an overly-large recv...
CVE-2022-24704CRITICAL9.8The rad_packet_recv function in opt/src/accel-pppd/radius/packet.c suffers from a buffer overflow vulnerability, whereby...
CVE-2022-23992CRITICAL9.8XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to insufficient input validat...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now