2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-40027MEDIUM6.1SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via...
CVE-2022-3251MEDIUM5.3Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2.
CVE-2022-3250MEDIUM5.3Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6.
CVE-2022-41255MEDIUM6.5Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins con...
CVE-2022-41254MEDIUM6.5Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to co...
CVE-2022-41252MEDIUM4.3Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enume...
CVE-2022-41251MEDIUM4.3A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier allows users with Overall/Read permission to enu...
CVE-2022-41250MEDIUM6.5A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permissio...
CVE-2022-41248MEDIUM5.3Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, ...
CVE-2022-41247MEDIUM4.3Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration f...
CVE-2022-41246MEDIUM6.5A missing permission check in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers with Ove...
CVE-2022-41242MEDIUM5.4A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permiss...
CVE-2022-41240MEDIUM5.4Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored ...
CVE-2022-41239MEDIUM5.4Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications...
CVE-2022-41235MEDIUM5.3Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary...
CVE-2022-41233MEDIUM4.3Jenkins Rundeck Plugin 3.6.11 and earlier does not perform Run/Artifacts permission checks in multiple HTTP endpoints, a...
CVE-2022-41231MEDIUM5.7Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any...
CVE-2022-41230MEDIUM4.3Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attack...
CVE-2022-41229MEDIUM5.4Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of th...
CVE-2022-41225MEDIUM5.4Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine...
CVE-2022-41224MEDIUM5.4Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help ...
CVE-2022-37246MEDIUM5.4Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput....
CVE-2022-3255MEDIUM4.8If an attacker can control a script that is executed in the victim's browser, then they can typically fully compromise t...
CVE-2022-2888MEDIUM4.4If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can...
CVE-2022-2795MEDIUM5.3By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's pe...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now