2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-37927 | MEDIUM | 6.1 | 0.4% | Dec 12, 2022 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Hewlett Packard Enterprise HPE OneView Global Dashb... |
| CVE-2022-37926 | MEDIUM | 5.4 | 0.5% | Dec 12, 2022 | A vulnerability within the web-based management interface of EdgeConnect Enterprise could allow a remote attacker to con... |
| CVE-2022-37925 | MEDIUM | 6.1 | 0.5% | Dec 12, 2022 | A vulnerability within the web-based management interface of Aruba EdgeConnect Enterprise could allow a remote attacker ... |
| CVE-2022-37911 | MEDIUM | 5.5 | 0.5% | Dec 12, 2022 | Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A ... |
| CVE-2022-37910 | MEDIUM | 6.5 | 0.6% | Dec 12, 2022 | A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerabil... |
| CVE-2022-37909 | MEDIUM | 5.3 | 0.3% | Dec 12, 2022 | Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the config... |
| CVE-2022-37908 | MEDIUM | 6.5 | 0.2% | Dec 12, 2022 | An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful expl... |
| CVE-2022-34318 | MEDIUM | 6.1 | 0.6% | Dec 12, 2022 | IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to v... |
| CVE-2022-32537 | MEDIUM | 4.8 | 0.3% | Dec 12, 2022 | A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pai... |
| CVE-2022-23511 | MEDIUM | 6.8 | 0.5% | Dec 12, 2022 | A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and ... |
| CVE-2022-22488 | MEDIUM | 4.9 | 0.5% | Dec 12, 2022 | IBM OpenBMC OP910 and OP940 could allow a privileged user to cause a denial of service by uploading or deleting too many... |
| CVE-2022-46688 | MEDIUM | 6.5 | 0.4% | Dec 12, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows at... |
| CVE-2022-46687 | MEDIUM | 5.4 | 0.5% | Dec 12, 2022 | Jenkins Spring Config Plugin 2.0.0 and earlier does not escape build display names shown on the Spring Config view, resu... |
| CVE-2022-46686 | MEDIUM | 5.4 | 0.5% | Dec 12, 2022 | Jenkins Custom Build Properties Plugin 2.79.vc095ccc85094 and earlier does not escape property values and build display ... |
| CVE-2022-46685 | MEDIUM | 4.3 | 0.3% | Dec 12, 2022 | In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credential... |
| CVE-2022-46684 | MEDIUM | 5.4 | 0.5% | Dec 12, 2022 | Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inse... |
| CVE-2022-46683 | MEDIUM | 6.1 | 0.5% | Dec 12, 2022 | Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is le... |
| CVE-2022-20691 | MEDIUM | 6.5 | 0.6% | Dec 12, 2022 | A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmwar... |
| CVE-2022-20688 | MEDIUM | 5.3 | 0.9% | Dec 12, 2022 | A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware ... |
| CVE-2022-20687 | MEDIUM | 5.3 | 0.9% | Dec 12, 2022 | Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Teleph... |
| CVE-2022-20686 | MEDIUM | 5.3 | 0.9% | Dec 12, 2022 | Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Teleph... |
| CVE-2022-31596 | MEDIUM | 6 | 0.7% | Dec 12, 2022 | Under certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Networ... |
| CVE-2022-45758 | MEDIUM | 5.4 | 0.3% | Dec 12, 2022 | SENS v1.0 is vulnerable to Cross Site Scripting (XSS) via com.liuyanzhao.sens.web.controller.admin, getRegister. |
| CVE-2022-45756 | MEDIUM | 6.1 | 0.3% | Dec 12, 2022 | SENS v1.0 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2022-44637 | MEDIUM | 6.1 | 0.4% | Dec 12, 2022 | Redmine before 4.2.9 and 5.0.x before 5.0.4 allows persistent XSS in its Textile formatter due to improper sanitization ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now