2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43417 | MEDIUM | 4.3 | 0.6% | Oct 19, 2022 | Jenkins Katalon Plugin 1.0.32 and earlier does not perform permission checks in several HTTP endpoints, allowing attacke... |
| CVE-2022-43414 | MEDIUM | 5.3 | 0.6% | Oct 19, 2022 | Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specifie... |
| CVE-2022-43413 | MEDIUM | 4.3 | 0.5% | Oct 19, 2022 | Jenkins Job Import Plugin 3.5 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers wi... |
| CVE-2022-43412 | MEDIUM | 5.3 | 0.5% | Oct 19, 2022 | Jenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whe... |
| CVE-2022-43411 | MEDIUM | 5.3 | 0.7% | Oct 19, 2022 | Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided... |
| CVE-2022-43410 | MEDIUM | 5.3 | 0.7% | Oct 19, 2022 | Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or schedu... |
| CVE-2022-43409 | MEDIUM | 5.4 | 0.7% | Oct 19, 2022 | Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of h... |
| CVE-2022-43408 | MEDIUM | 6.5 | 0.4% | Oct 19, 2022 | Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to ... |
| CVE-2022-43185 | MEDIUM | 5.4 | 1.0% | Oct 19, 2022 | A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows atta... |
| CVE-2022-43045 | MEDIUM | 5.5 | 0.3% | Oct 19, 2022 | GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_dump_vrml_s... |
| CVE-2022-43044 | MEDIUM | 5.5 | 0.3% | Oct 19, 2022 | GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_get_me... |
| CVE-2022-43043 | MEDIUM | 5.5 | 0.3% | Oct 19, 2022 | GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function BD_CheckSFTime... |
| CVE-2022-43039 | MEDIUM | 5.5 | 0.3% | Oct 19, 2022 | GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_meta_r... |
| CVE-2022-43038 | MEDIUM | 6.5 | 0.6% | Oct 19, 2022 | Bento4 v1.6.0-639 was discovered to contain a heap overflow via the AP4_BitReader::ReadCache() function in mp42ts. |
| CVE-2022-43037 | MEDIUM | 6.5 | 0.6% | Oct 19, 2022 | An issue was discovered in Bento4 1.6.0-639. There is a memory leak in the function AP4_File::ParseStream in /Core/Ap4Fi... |
| CVE-2022-43035 | MEDIUM | 6.5 | 0.6% | Oct 19, 2022 | An issue was discovered in Bento4 v1.6.0-639. There is a heap-buffer-overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3At... |
| CVE-2022-43034 | MEDIUM | 6.5 | 0.6% | Oct 19, 2022 | An issue was discovered in Bento4 v1.6.0-639. There is a heap buffer overflow vulnerability in the AP4_BitReader::SkipBi... |
| CVE-2022-43033 | MEDIUM | 6.5 | 0.6% | Oct 19, 2022 | An issue was discovered in Bento4 1.6.0-639. There is a bad free in the component AP4_HdlrAtom::~AP4_HdlrAtom() which al... |
| CVE-2022-43032 | MEDIUM | 6.5 | 0.6% | Oct 19, 2022 | An issue was discovered in Bento4 v1.6.0-639. There is a memory leak in AP4_DescriptorFactory::CreateDescriptorFromStrea... |
| CVE-2022-39301 | MEDIUM | 5.4 | 0.5% | Oct 19, 2022 | sra-admin is a background rights management system that separates the front and back end. sra-admin version 1.1.1 has a ... |
| CVE-2022-3607 | MEDIUM | 6 | 0.4% | Oct 19, 2022 | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/o... |
| CVE-2022-39253 | MEDIUM | 5.5 | 1.3% | Oct 19, 2022 | Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, ... |
| CVE-2022-39233 | MEDIUM | 5.4 | 0.6% | Oct 19, 2022 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions 12.9.... |
| CVE-2022-25666 | MEDIUM | 6.7 | 0.1% | Oct 19, 2022 | Memory corruption due to use after free in service while trying to access maps by different threads in Snapdragon Auto, ... |
| CVE-2022-25664 | MEDIUM | 5.5 | 0.2% | Oct 19, 2022 | Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, S... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now