2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-35895 | HIGH | 8.2 | 0.3% | Sep 21, 2022 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The FwBlockSericceSmm driver does not properly ... |
| CVE-2022-40217 | HIGH | 7.2 | 0.9% | Sep 21, 2022 | Authenticated (admin+) Arbitrary File Edit/Upload vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress. |
| CVE-2022-36386 | HIGH | 7.2 | 1.1% | Sep 21, 2022 | Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 a... |
| CVE-2022-3252 | HIGH | 7.5 | 0.7% | Sep 21, 2022 | Improper detection of complete HTTP body decompression SwiftNIO Extras provides a pair of helpers for transparently deco... |
| CVE-2022-23952 | HIGH | 7.5 | 1.1% | Sep 21, 2022 | In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as ... |
| CVE-2022-23950 | HIGH | 7.5 | 1.2% | Sep 21, 2022 | In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged ... |
| CVE-2022-23949 | HIGH | 7.5 | 1.0% | Sep 21, 2022 | In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier a... |
| CVE-2022-23948 | HIGH | 7.5 | 1.1% | Sep 21, 2022 | A flaw was found in Keylime before 6.3.0. The logic in the Keylime agent for checking for a secure mount can be fooled b... |
| CVE-2022-40026 | HIGH | 7.2 | 0.7% | Sep 21, 2022 | SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId p... |
| CVE-2022-40616 | HIGH | 8.1 | 0.5% | Sep 21, 2022 | IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensiti... |
| CVE-2022-37027 | HIGH | 7.2 | 20.8% | Sep 21, 2022 | Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can... |
| CVE-2022-41253 | HIGH | 8.8 | 0.5% | Sep 21, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins CONS3RT Plugin 1.0.0 and earlier allows attackers to connec... |
| CVE-2022-41249 | HIGH | 8.8 | 0.4% | Sep 21, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers to c... |
| CVE-2022-41245 | HIGH | 8.8 | 0.4% | Sep 21, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier al... |
| CVE-2022-41244 | HIGH | 8.1 | 0.5% | Sep 21, 2022 | Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the confi... |
| CVE-2022-41243 | HIGH | 8.1 | 0.5% | Sep 21, 2022 | Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26... |
| CVE-2022-41236 | HIGH | 8.8 | 0.4% | Sep 21, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Security Inspector Plugin 117.v6eecc36919c2 and earlier all... |
| CVE-2022-41234 | HIGH | 8.8 | 0.8% | Sep 21, 2022 | Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing use... |
| CVE-2022-41232 | HIGH | 8 | 0.4% | Sep 21, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers to... |
| CVE-2022-41228 | HIGH | 8.8 | 0.8% | Sep 21, 2022 | A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attack... |
| CVE-2022-41227 | HIGH | 8.8 | 0.4% | Sep 21, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 an... |
| CVE-2022-2265 | HIGH | 7.5 | 0.7% | Sep 21, 2022 | The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauth... |
| CVE-2022-38928 | HIGH | 7.8 | 0.4% | Sep 21, 2022 | XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393. |
| CVE-2022-3068 | HIGH | 8.8 | 0.4% | Sep 21, 2022 | Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3. |
| CVE-2022-3080 | HIGH | 7.5 | 1.5% | Sep 21, 2022 | By sending specific queries to the resolver, an attacker can cause named to crash. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now