2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-35895HIGH8.2An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The FwBlockSericceSmm driver does not properly ...
CVE-2022-40217HIGH7.2Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
CVE-2022-36386HIGH7.2Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 a...
CVE-2022-3252HIGH7.5Improper detection of complete HTTP body decompression SwiftNIO Extras provides a pair of helpers for transparently deco...
CVE-2022-23952HIGH7.5In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as ...
CVE-2022-23950HIGH7.5In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged ...
CVE-2022-23949HIGH7.5In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier a...
CVE-2022-23948HIGH7.5A flaw was found in Keylime before 6.3.0. The logic in the Keylime agent for checking for a secure mount can be fooled b...
CVE-2022-40026HIGH7.2SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId p...
CVE-2022-40616HIGH8.1IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensiti...
CVE-2022-37027HIGH7.2Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can...
CVE-2022-41253HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins CONS3RT Plugin 1.0.0 and earlier allows attackers to connec...
CVE-2022-41249HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers to c...
CVE-2022-41245HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier al...
CVE-2022-41244HIGH8.1Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the confi...
CVE-2022-41243HIGH8.1Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26...
CVE-2022-41236HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Security Inspector Plugin 117.v6eecc36919c2 and earlier all...
CVE-2022-41234HIGH8.8Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing use...
CVE-2022-41232HIGH8A cross-site request forgery (CSRF) vulnerability in Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers to...
CVE-2022-41228HIGH8.8A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attack...
CVE-2022-41227HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 an...
CVE-2022-2265HIGH7.5The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauth...
CVE-2022-38928HIGH7.8XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.
CVE-2022-3068HIGH8.8Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.
CVE-2022-3080HIGH7.5By sending specific queries to the resolver, an attacker can cause named to crash.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now