2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-37927MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashb...
CVE-2022-37926MEDIUM5.4A vulnerability within the web-based management interface of EdgeConnect Enterprise could allow a remote attacker to con...
CVE-2022-37925MEDIUM6.1A vulnerability within the web-based management interface of Aruba EdgeConnect Enterprise could allow a remote attacker ...
CVE-2022-37911MEDIUM5.5Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A ...
CVE-2022-37910MEDIUM6.5A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerabil...
CVE-2022-37909MEDIUM5.3Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the config...
CVE-2022-37908MEDIUM6.5An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful expl...
CVE-2022-34318MEDIUM6.1 IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to v...
CVE-2022-32537MEDIUM4.8A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pai...
CVE-2022-23511MEDIUM6.8A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and ...
CVE-2022-22488MEDIUM4.9IBM OpenBMC OP910 and OP940 could allow a privileged user to cause a denial of service by uploading or deleting too many...
CVE-2022-46688MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows at...
CVE-2022-46687MEDIUM5.4Jenkins Spring Config Plugin 2.0.0 and earlier does not escape build display names shown on the Spring Config view, resu...
CVE-2022-46686MEDIUM5.4Jenkins Custom Build Properties Plugin 2.79.vc095ccc85094 and earlier does not escape property values and build display ...
CVE-2022-46685MEDIUM4.3In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credential...
CVE-2022-46684MEDIUM5.4Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inse...
CVE-2022-46683MEDIUM6.1Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is le...
CVE-2022-20691MEDIUM6.5A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmwar...
CVE-2022-20688MEDIUM5.3A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware ...
CVE-2022-20687MEDIUM5.3Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Teleph...
CVE-2022-20686MEDIUM5.3Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Teleph...
CVE-2022-31596MEDIUM6Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Networ...
CVE-2022-45758MEDIUM5.4SENS v1.0 is vulnerable to Cross Site Scripting (XSS) via com.liuyanzhao.sens.web.controller.admin, getRegister.
CVE-2022-45756MEDIUM6.1SENS v1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2022-44637MEDIUM6.1Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now