2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-40027 | MEDIUM | 6.1 | 0.7% | Sep 21, 2022 | SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via... |
| CVE-2022-3251 | MEDIUM | 5.3 | 0.5% | Sep 21, 2022 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2. |
| CVE-2022-3250 | MEDIUM | 5.3 | 0.4% | Sep 21, 2022 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6. |
| CVE-2022-41255 | MEDIUM | 6.5 | 0.7% | Sep 21, 2022 | Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins con... |
| CVE-2022-41254 | MEDIUM | 6.5 | 0.7% | Sep 21, 2022 | Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to co... |
| CVE-2022-41252 | MEDIUM | 4.3 | 0.5% | Sep 21, 2022 | Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enume... |
| CVE-2022-41251 | MEDIUM | 4.3 | 0.5% | Sep 21, 2022 | A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier allows users with Overall/Read permission to enu... |
| CVE-2022-41250 | MEDIUM | 6.5 | 0.5% | Sep 21, 2022 | A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permissio... |
| CVE-2022-41248 | MEDIUM | 5.3 | 0.3% | Sep 21, 2022 | Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, ... |
| CVE-2022-41247 | MEDIUM | 4.3 | 0.4% | Sep 21, 2022 | Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration f... |
| CVE-2022-41246 | MEDIUM | 6.5 | 0.6% | Sep 21, 2022 | A missing permission check in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers with Ove... |
| CVE-2022-41242 | MEDIUM | 5.4 | 0.4% | Sep 21, 2022 | A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permiss... |
| CVE-2022-41240 | MEDIUM | 5.4 | 0.5% | Sep 21, 2022 | Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored ... |
| CVE-2022-41239 | MEDIUM | 5.4 | 0.6% | Sep 21, 2022 | Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications... |
| CVE-2022-41235 | MEDIUM | 5.3 | 0.6% | Sep 21, 2022 | Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary... |
| CVE-2022-41233 | MEDIUM | 4.3 | 0.5% | Sep 21, 2022 | Jenkins Rundeck Plugin 3.6.11 and earlier does not perform Run/Artifacts permission checks in multiple HTTP endpoints, a... |
| CVE-2022-41231 | MEDIUM | 5.7 | 1.2% | Sep 21, 2022 | Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any... |
| CVE-2022-41230 | MEDIUM | 4.3 | 0.5% | Sep 21, 2022 | Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attack... |
| CVE-2022-41229 | MEDIUM | 5.4 | 0.5% | Sep 21, 2022 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of th... |
| CVE-2022-41225 | MEDIUM | 5.4 | 0.6% | Sep 21, 2022 | Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine... |
| CVE-2022-41224 | MEDIUM | 5.4 | 0.9% | Sep 21, 2022 | Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help ... |
| CVE-2022-37246 | MEDIUM | 5.4 | 0.4% | Sep 21, 2022 | Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.... |
| CVE-2022-3255 | MEDIUM | 4.8 | 0.6% | Sep 21, 2022 | If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise t... |
| CVE-2022-2888 | MEDIUM | 4.4 | 0.3% | Sep 21, 2022 | If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can... |
| CVE-2022-2795 | MEDIUM | 5.3 | 1.4% | Sep 21, 2022 | By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's pe... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now