2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22773 | MEDIUM | 5.4 | 0.5% | May 17, 2022 | The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server - Community Editi... |
| CVE-2022-1706 | MEDIUM | 6.5 | 1.1% | May 17, 2022 | A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running ... |
| CVE-2022-30072 | MEDIUM | 5.4 | 0.8% | May 17, 2022 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters. |
| CVE-2022-30067 | MEDIUM | 5.5 | 0.7% | May 17, 2022 | GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a ... |
| CVE-2022-22482 | MEDIUM | 6.5 | 0.9% | May 17, 2022 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenti... |
| CVE-2022-22475 | MEDIUM | 6.5 | 0.6% | May 17, 2022 | IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing ... |
| CVE-2022-30073 | MEDIUM | 5.4 | 1.5% | May 17, 2022 | WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php. |
| CVE-2022-22484 | MEDIUM | 5.5 | 0.2% | May 17, 2022 | IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, c... |
| CVE-2022-30970 | MEDIUM | 5.4 | 0.7% | May 17, 2022 | Jenkins Autocomplete Parameter Plugin 1.1 and earlier references Dropdown Autocomplete parameter and Auto Complete Strin... |
| CVE-2022-30968 | MEDIUM | 5.4 | 0.7% | May 17, 2022 | Jenkins vboxwrapper Plugin 1.3 and earlier does not escape the name and description of VBox node parameters on views dis... |
| CVE-2022-30967 | MEDIUM | 5.4 | 0.7% | May 17, 2022 | Jenkins Selection tasks Plugin 1.0 and earlier does not escape the name and description of Script Selection task variabl... |
| CVE-2022-30966 | MEDIUM | 5.4 | 0.7% | May 17, 2022 | Jenkins Random String Parameter Plugin 1.0 and earlier does not escape the name and description of Random String paramet... |
| CVE-2022-30965 | MEDIUM | 5.4 | 0.7% | May 17, 2022 | Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level para... |
| CVE-2022-30964 | MEDIUM | 5.4 | 0.7% | May 17, 2022 | Jenkins Multiselect parameter Plugin 1.3 and earlier does not escape the name and description of Multiselect parameters ... |
| CVE-2022-30963 | MEDIUM | 5.4 | 0.7% | May 17, 2022 | Jenkins JDK Parameter Plugin 1.0 and earlier does not escape the name and description of JDK parameters on views display... |
| CVE-2022-30962 | MEDIUM | 5.4 | 0.7% | May 17, 2022 | Jenkins Global Variable String Parameter Plugin 1.2 and earlier does not escape the name and description of Global Varia... |
| CVE-2022-30961 | MEDIUM | 5.4 | 0.7% | May 17, 2022 | Jenkins Autocomplete Parameter Plugin 1.1 and earlier does not escape the name of Dropdown Autocomplete and Auto Complet... |
| CVE-2022-30960 | MEDIUM | 5.4 | 0.7% | May 17, 2022 | Jenkins Application Detector Plugin 1.0.8 and earlier does not escape the name of Chois Application Version parameters o... |
| CVE-2022-30959 | MEDIUM | 6.5 | 0.8% | May 17, 2022 | A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to conn... |
| CVE-2022-30957 | MEDIUM | 4.3 | 0.7% | May 17, 2022 | A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to enum... |
| CVE-2022-30956 | MEDIUM | 5.4 | 71.3% | May 17, 2022 | Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a s... |
| CVE-2022-30955 | MEDIUM | 6.5 | 0.8% | May 17, 2022 | Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers wit... |
| CVE-2022-30954 | MEDIUM | 6.5 | 0.8% | May 17, 2022 | Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing att... |
| CVE-2022-30953 | MEDIUM | 6.5 | 0.6% | May 17, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to co... |
| CVE-2022-30952 | MEDIUM | 6.5 | 0.9% | May 17, 2022 | Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to acce... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now