2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43017 | MEDIUM | 6.1 | 1.3% | Oct 19, 2022 | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the indexFile compone... |
| CVE-2022-43016 | MEDIUM | 6.1 | 1.3% | Oct 19, 2022 | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the callback componen... |
| CVE-2022-43015 | MEDIUM | 6.1 | 1.3% | Oct 19, 2022 | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the entriesPerPage pa... |
| CVE-2022-43014 | MEDIUM | 6.1 | 1.3% | Oct 19, 2022 | OpenCATS v0.9.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the joborderID parame... |
| CVE-2022-40885 | MEDIUM | 5.5 | 0.2% | Oct 19, 2022 | Bento4 v1.6.0-639 has a memory allocation issue that can cause denial of service. |
| CVE-2022-40884 | MEDIUM | 5.5 | 0.3% | Oct 19, 2022 | Bento4 1.6.0 has memory leaks via the mp4fragment. |
| CVE-2022-3586 | MEDIUM | 5.5 | 0.4% | Oct 19, 2022 | A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue functi... |
| CVE-2022-2805 | MEDIUM | 6.5 | 0.4% | Oct 19, 2022 | A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-sty... |
| CVE-2022-41707 | MEDIUM | 6.5 | 0.8% | Oct 19, 2022 | Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access sensitive data of any user o... |
| CVE-2022-43435 | MEDIUM | 5.3 | 0.6% | Oct 19, 2022 | Jenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-gene... |
| CVE-2022-43434 | MEDIUM | 5.3 | 0.6% | Oct 19, 2022 | Jenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protec... |
| CVE-2022-43433 | MEDIUM | 4.3 | 0.5% | Oct 19, 2022 | Jenkins ScreenRecorder Plugin 0.7 and earlier programmatically disables Content-Security-Policy protection for user-gene... |
| CVE-2022-43432 | MEDIUM | 4.3 | 0.5% | Oct 19, 2022 | Jenkins XFramium Builder Plugin 1.0.22 and earlier programmatically disables Content-Security-Policy protection for user... |
| CVE-2022-43431 | MEDIUM | 4.3 | 0.4% | Oct 19, 2022 | Jenkins Compuware Strobe Measurement Plugin 1.0.1 and earlier does not perform a permission check in an HTTP endpoint, a... |
| CVE-2022-43428 | MEDIUM | 5.3 | 0.6% | Oct 19, 2022 | Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not lim... |
| CVE-2022-43427 | MEDIUM | 4.3 | 0.5% | Oct 19, 2022 | Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpo... |
| CVE-2022-43426 | MEDIUM | 5.3 | 0.5% | Oct 19, 2022 | Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potentia... |
| CVE-2022-43425 | MEDIUM | 5.4 | 0.8% | Oct 19, 2022 | Jenkins Custom Checkbox Parameter Plugin 1.4 and earlier does not escape the name and description of Custom Checkbox Par... |
| CVE-2022-43424 | MEDIUM | 5.3 | 0.6% | Oct 19, 2022 | Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not l... |
| CVE-2022-43423 | MEDIUM | 5.3 | 0.6% | Oct 19, 2022 | Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier implements an agent/controll... |
| CVE-2022-43422 | MEDIUM | 5.3 | 0.7% | Oct 19, 2022 | Jenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier implements an agent/controller message that does not limit wh... |
| CVE-2022-43421 | MEDIUM | 5.3 | 0.7% | Oct 19, 2022 | A missing permission check in Jenkins Tuleap Git Branch Source Plugin 3.2.4 and earlier allows unauthenticated attackers... |
| CVE-2022-43420 | MEDIUM | 5.4 | 0.6% | Oct 19, 2022 | Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast ... |
| CVE-2022-43419 | MEDIUM | 6.5 | 0.7% | Oct 19, 2022 | Jenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller ... |
| CVE-2022-43418 | MEDIUM | 4.3 | 0.4% | Oct 19, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Katalon Plugin 1.0.33 and earlier allows attackers to conne... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now