2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45380 | MEDIUM | 5.4 | 0.6% | Nov 15, 2022 | Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in a... |
| CVE-2022-41558 | MEDIUM | 5.4 | 0.5% | Nov 15, 2022 | The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Ana... |
| CVE-2022-43071 | MEDIUM | 5.5 | 0.3% | Nov 15, 2022 | A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial o... |
| CVE-2022-3997 | MEDIUM | 6.1 | 0.4% | Nov 15, 2022 | A vulnerability, which was classified as critical, has been found in MonikaBrzica scm. Affected by this issue is some un... |
| CVE-2022-42001 | MEDIUM | 5.4 | 0.3% | Nov 15, 2022 | Cross-site Scripting (XSS) vulnerability in BlueSpiceBookshelf extension of BlueSpice allows user with regular account a... |
| CVE-2022-42000 | MEDIUM | 5.4 | 0.3% | Nov 15, 2022 | Cross-site Scripting (XSS) vulnerability in BlueSpiceSocialProfile extension of BlueSpice allows user with comment permi... |
| CVE-2022-41814 | MEDIUM | 5.4 | 0.3% | Nov 15, 2022 | Cross-site Scripting (XSS) vulnerability in BlueSpiceFoundation extension of BlueSpice allows user with regular account ... |
| CVE-2022-41789 | MEDIUM | 5.4 | 0.3% | Nov 15, 2022 | Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows logged in user with edit permiss... |
| CVE-2022-41611 | MEDIUM | 4.8 | 0.3% | Nov 15, 2022 | Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows user with admin privileges to in... |
| CVE-2022-3958 | MEDIUM | 5.4 | 0.3% | Nov 15, 2022 | Cross-site Scripting (XSS) vulnerability in BlueSpiceUserSidebar extension of BlueSpice allows user with regular account... |
| CVE-2022-3895 | MEDIUM | 6.1 | 0.3% | Nov 15, 2022 | Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output... |
| CVE-2022-3893 | MEDIUM | 4.8 | 0.3% | Nov 15, 2022 | Cross-site Scripting (XSS) vulnerability in BlueSpiceCustomMenu extension of BlueSpice allows user with admin permission... |
| CVE-2022-40309 | MEDIUM | 4.3 | 1.4% | Nov 15, 2022 | Users with write permissions to a repository can delete arbitrary directories. |
| CVE-2022-25679 | MEDIUM | 5.5 | 0.1% | Nov 15, 2022 | Denial of service in video due to improper access control in broadcast receivers in Snapdragon Compute, Snapdragon Consu... |
| CVE-2022-25676 | MEDIUM | 5.5 | 0.1% | Nov 15, 2022 | Information disclosure in video due to buffer over-read while parsing avi files in Snapdragon Auto, Snapdragon Compute, ... |
| CVE-2022-45402 | MEDIUM | 6.1 | 81.8% | Nov 15, 2022 | In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint. |
| CVE-2022-40846 | MEDIUM | 4.8 | 0.6% | Nov 15, 2022 | In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scripting (XSS) vulnerability exists allowing... |
| CVE-2022-40844 | MEDIUM | 5.4 | 0.5% | Nov 15, 2022 | In Tenda (Shenzhen Tenda Technology Co., Ltd) AC1200 Router model W15Ev2 V15.11.0.10(1576), a Stored Cross Site Scriptin... |
| CVE-2022-42132 | MEDIUM | 5.9 | 0.6% | Nov 15, 2022 | The Test LDAP Users functionality in Liferay Portal 7.0.0 through 7.4.3.4, and Liferay DXP 7.0 fix pack 102 and earlier,... |
| CVE-2022-42131 | MEDIUM | 4.8 | 0.3% | Nov 15, 2022 | Certain Liferay products are affected by: Missing SSL Certificate Validation in the Dynamic Data Mapping module's REST d... |
| CVE-2022-42130 | MEDIUM | 4.3 | 0.7% | Nov 15, 2022 | The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.4.3.4, and Liferay DXP 7.1 before fix pack 27, 7.2 bef... |
| CVE-2022-42129 | MEDIUM | 4.3 | 0.7% | Nov 15, 2022 | An Insecure direct object reference (IDOR) vulnerability in the Dynamic Data Mapping module in Liferay Portal 7.3.2 thro... |
| CVE-2022-40845 | MEDIUM | 6.5 | 0.7% | Nov 15, 2022 | The Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576) is affected by a password exposure vulnerability. When combined w... |
| CVE-2022-40843 | MEDIUM | 4.9 | 28.8% | Nov 15, 2022 | The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management... |
| CVE-2022-42128 | MEDIUM | 5.3 | 0.8% | Nov 15, 2022 | The Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now