2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-36902MEDIUM5.4Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape several fields of Moded Extended Choi...
CVE-2022-36901MEDIUM6.5Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file ...
CVE-2022-36898MEDIUM4.3A missing permission check in Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier allows attackers with Overall/R...
CVE-2022-36897MEDIUM4.3A missing permission check in Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier allows attackers with Ov...
CVE-2022-36896MEDIUM6.5A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlie...
CVE-2022-36895MEDIUM4.3A missing permission check in Jenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier allows attackers with Overall/R...
CVE-2022-36894MEDIUM6.5An arbitrary file write vulnerability in Jenkins CLIF Performance Testing Plugin 64.vc0d66de1dfb_f and earlier allows at...
CVE-2022-36893MEDIUM4.3Jenkins rpmsign-plugin Plugin 0.5.0 and earlier does not perform a permission check in a method implementing form valida...
CVE-2022-36892MEDIUM4.3Jenkins rhnpush-plugin Plugin 0.5.1 and earlier does not perform a permission check in a method implementing form valida...
CVE-2022-36891MEDIUM4.3A missing permission check in Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier allows attackers with Item/...
CVE-2022-36890MEDIUM4.3Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the name of files in methods implementi...
CVE-2022-36888MEDIUM6.5A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overa...
CVE-2022-36887MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and ...
CVE-2022-36886MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins External Monitor Job Type Plugin 191.v363d0d1efdf8 and earl...
CVE-2022-36885MEDIUM5.3Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided...
CVE-2022-36884MEDIUM5.3The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the ex...
CVE-2022-2549MEDIUM5.5NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV.
CVE-2022-34551MEDIUM6.5Sims v1.0 was discovered to allow path traversal when downloading attachments.
CVE-2022-34550MEDIUM5.4Sims v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /addNotifyServlet. This...
CVE-2022-34529MEDIUM5.5WASM3 v0.5.0 was discovered to contain a segmentation fault via the component Compile_Memory_CopyFill.
CVE-2022-24406MEDIUM6.5OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to inj...
CVE-2022-23101MEDIUM6.1OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.
CVE-2022-23099MEDIUM5.4OX App Suite through 7.10.6 allows XSS by forcing block-wise read.
CVE-2022-36880MEDIUM6.1The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.
CVE-2022-36879MEDIUM5.5An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now