2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-22773MEDIUM5.4The REST API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server - Community Editi...
CVE-2022-1706MEDIUM6.5A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running ...
CVE-2022-30072MEDIUM5.4WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via \admin\pages\sections_save.php namesection2 parameters.
CVE-2022-30067MEDIUM5.5GIMP 2.10.30 and 2.99.10 are vulnerable to Buffer Overflow. Through a crafted XCF file, the program will allocate for a ...
CVE-2022-22482MEDIUM6.5IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow an authenti...
CVE-2022-22475MEDIUM6.5IBM WebSphere Application Server Liberty and Open Liberty 17.0.0.3 through 22.0.0.5 are vulnerable to identity spoofing ...
CVE-2022-30073MEDIUM5.4WBCE CMS 1.5.2 is vulnerable to Cross Site Scripting (XSS) via /admin/users/save.php.
CVE-2022-22484MEDIUM5.5IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, c...
CVE-2022-30970MEDIUM5.4Jenkins Autocomplete Parameter Plugin 1.1 and earlier references Dropdown Autocomplete parameter and Auto Complete Strin...
CVE-2022-30968MEDIUM5.4Jenkins vboxwrapper Plugin 1.3 and earlier does not escape the name and description of VBox node parameters on views dis...
CVE-2022-30967MEDIUM5.4Jenkins Selection tasks Plugin 1.0 and earlier does not escape the name and description of Script Selection task variabl...
CVE-2022-30966MEDIUM5.4Jenkins Random String Parameter Plugin 1.0 and earlier does not escape the name and description of Random String paramet...
CVE-2022-30965MEDIUM5.4Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level para...
CVE-2022-30964MEDIUM5.4Jenkins Multiselect parameter Plugin 1.3 and earlier does not escape the name and description of Multiselect parameters ...
CVE-2022-30963MEDIUM5.4Jenkins JDK Parameter Plugin 1.0 and earlier does not escape the name and description of JDK parameters on views display...
CVE-2022-30962MEDIUM5.4Jenkins Global Variable String Parameter Plugin 1.2 and earlier does not escape the name and description of Global Varia...
CVE-2022-30961MEDIUM5.4Jenkins Autocomplete Parameter Plugin 1.1 and earlier does not escape the name of Dropdown Autocomplete and Auto Complet...
CVE-2022-30960MEDIUM5.4Jenkins Application Detector Plugin 1.0.8 and earlier does not escape the name of Chois Application Version parameters o...
CVE-2022-30959MEDIUM6.5A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to conn...
CVE-2022-30957MEDIUM4.3A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to enum...
CVE-2022-30956MEDIUM5.4Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a s...
CVE-2022-30955MEDIUM6.5Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers wit...
CVE-2022-30954MEDIUM6.5Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing att...
CVE-2022-30953MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to co...
CVE-2022-30952MEDIUM6.5Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to acce...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now