2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34785 | MEDIUM | 4.3 | 0.6% | Jun 30, 2022 | Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing att... |
| CVE-2022-34784 | MEDIUM | 5.4 | 0.7% | Jun 30, 2022 | Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-... |
| CVE-2022-34783 | MEDIUM | 5.4 | 80.4% | Jun 30, 2022 | Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XS... |
| CVE-2022-34782 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read pe... |
| CVE-2022-34781 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read pe... |
| CVE-2022-34780 | MEDIUM | 6.5 | 0.4% | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attac... |
| CVE-2022-34779 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | A missing permission check in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers with Overall/Read ... |
| CVE-2022-34778 | MEDIUM | 5.4 | 0.5% | Jun 30, 2022 | Jenkins TestNG Results Plugin 554.va4a552116332 and earlier renders the unescaped test descriptions and exception messag... |
| CVE-2022-34777 | MEDIUM | 5.4 | 72.4% | Jun 30, 2022 | Jenkins GitLab Plugin 1.5.34 and earlier does not escape multiple fields inserted into the description of webhook-trigge... |
| CVE-2022-22496 | MEDIUM | 6.5 | 0.4% | Jun 30, 2022 | While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be config... |
| CVE-2022-22494 | MEDIUM | 5.3 | 1.3% | Jun 30, 2022 | IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the dat... |
| CVE-2022-22478 | MEDIUM | 5.5 | 0.2% | Jun 30, 2022 | IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a ... |
| CVE-2022-2058 | MEDIUM | 6.5 | 1.0% | Jun 30, 2022 | Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file.... |
| CVE-2022-2057 | MEDIUM | 6.5 | 1.0% | Jun 30, 2022 | Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file.... |
| CVE-2022-2056 | MEDIUM | 6.5 | 1.0% | Jun 30, 2022 | Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file.... |
| CVE-2022-1955 | MEDIUM | 4.6 | 0.4% | Jun 30, 2022 | Session 1.13.0 allows an attacker with physical access to the victim's device to bypass the application's password/pin l... |
| CVE-2022-33043 | MEDIUM | 5.4 | 0.5% | Jun 30, 2022 | A cross-site scripting (XSS) vulnerability in the batch add function of Urtracker Premium v4.0.1.1477 allows attackers t... |
| CVE-2022-2078 | MEDIUM | 5.5 | 1.0% | Jun 30, 2022 | A vulnerability was found in the Linux kernel's nft_set_desc_concat_parse() function .This flaw allows an attacker to tr... |
| CVE-2022-1852 | MEDIUM | 5.5 | 0.3% | Jun 30, 2022 | A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the... |
| CVE-2022-26135 | MEDIUM | 6.5 | 71.2% | Jun 30, 2022 | A vulnerability in Mobile Plugin for Jira Data Center and Server allows a remote, authenticated user (including a user w... |
| CVE-2022-30467 | MEDIUM | 6.8 | 0.8% | Jun 29, 2022 | Joy ebike Wolf Manufacturing year 2022 is vulnerable to Denial of service, which allows remote attackers to jam the key ... |
| CVE-2022-31063 | MEDIUM | 5.4 | 0.5% | Jun 29, 2022 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior... |
| CVE-2022-31032 | MEDIUM | 4.3 | 0.7% | Jun 29, 2022 | Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In versions prior... |
| CVE-2022-2252 | MEDIUM | 6.1 | 0.8% | Jun 29, 2022 | Open Redirect in GitHub repository microweber/microweber prior to 1.2.19. |
| CVE-2022-32969 | MEDIUM | 5.9 | 1.2% | Jun 29, 2022 | MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now