2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-37018 | HIGH | 8.4 | 0.2% | Dec 12, 2022 | A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation o... |
| CVE-2022-34318 | MEDIUM | 6.1 | 0.6% | Dec 12, 2022 | IBM CICS TX 11.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to v... |
| CVE-2022-32537 | MEDIUM | 4.8 | 0.3% | Dec 12, 2022 | A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pai... |
| CVE-2022-2794 | HIGH | 7.5 | 0.9% | Dec 12, 2022 | Certain HP PageWide Pro Printers may be vulnerable to a potential denial of service attack. |
| CVE-2022-23511 | MEDIUM | 6.8 | 0.5% | Dec 12, 2022 | A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and ... |
| CVE-2022-22488 | MEDIUM | 4.9 | 0.5% | Dec 12, 2022 | IBM OpenBMC OP910 and OP940 could allow a privileged user to cause a denial of service by uploading or deleting too many... |
| CVE-2022-1038 | HIGH | 7.8 | 0.2% | Dec 12, 2022 | A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of pri... |
| CVE-2022-3485 | CRITICAL | 9.8 | 0.9% | Dec 12, 2022 | In IFM Moneo Appliance with version up to 1.9.3 an unauthenticated remote attacker can reset the administrator password ... |
| CVE-2022-46688 | MEDIUM | 6.5 | 0.4% | Dec 12, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows at... |
| CVE-2022-46687 | MEDIUM | 5.4 | 0.5% | Dec 12, 2022 | Jenkins Spring Config Plugin 2.0.0 and earlier does not escape build display names shown on the Spring Config view, resu... |
| CVE-2022-46686 | MEDIUM | 5.4 | 0.5% | Dec 12, 2022 | Jenkins Custom Build Properties Plugin 2.79.vc095ccc85094 and earlier does not escape property values and build display ... |
| CVE-2022-46685 | MEDIUM | 4.3 | 0.3% | Dec 12, 2022 | In Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did not support credential... |
| CVE-2022-46684 | MEDIUM | 5.4 | 0.5% | Dec 12, 2022 | Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inse... |
| CVE-2022-46683 | MEDIUM | 6.1 | 0.5% | Dec 12, 2022 | Jenkins Google Login Plugin 1.4 through 1.6 (both inclusive) improperly determines that a redirect URL after login is le... |
| CVE-2022-46682 | CRITICAL | 9.8 | 0.9% | Dec 12, 2022 | Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2022-45797 | HIGH | 7.1 | 0.6% | Dec 12, 2022 | An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro ... |
| CVE-2022-41296 | HIGH | 8.8 | 0.5% | Dec 12, 2022 | IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute maliciou... |
| CVE-2022-3641 | HIGH | 8.8 | 0.6% | Dec 12, 2022 | Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows ... |
| CVE-2022-20968 | HIGH | 8.8 | 6.4% | Dec 12, 2022 | A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could... |
| CVE-2022-20691 | MEDIUM | 6.5 | 0.6% | Dec 12, 2022 | A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmwar... |
| CVE-2022-20690 | HIGH | 8.8 | 0.7% | Dec 12, 2022 | Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter ... |
| CVE-2022-20689 | HIGH | 8.8 | 0.6% | Dec 12, 2022 | Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter ... |
| CVE-2022-20688 | MEDIUM | 5.3 | 0.9% | Dec 12, 2022 | A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware ... |
| CVE-2022-20687 | MEDIUM | 5.3 | 0.9% | Dec 12, 2022 | Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Teleph... |
| CVE-2022-20686 | MEDIUM | 5.3 | 0.9% | Dec 12, 2022 | Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Teleph... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now