2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-30949 | MEDIUM | 5.3 | 1.0% | May 17, 2022 | Jenkins REPO Plugin 1.14.0 and earlier allows attackers able to configure pipelines to check out some SCM repositories s... |
| CVE-2022-30946 | MEDIUM | 4.3 | 0.6% | May 17, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Script Security Plugin 1158.v7c1b_73a_69a_08 and earlier al... |
| CVE-2022-30110 | MEDIUM | 6.1 | 0.5% | May 17, 2022 | The file preview functionality in Jirafeau < 4.4.0, which is enabled by default, could be exploited for cross site scrip... |
| CVE-2022-29332 | MEDIUM | 6.5 | 1.4% | May 17, 2022 | D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the F... |
| CVE-2022-1753 | MEDIUM | 4.3 | 0.9% | May 17, 2022 | A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is re... |
| CVE-2022-23670 | MEDIUM | 6.5 | 1.0% | May 16, 2022 | A remote authenticated information disclosure vulnerability was discovered in Aruba ClearPass Policy Manager version(s):... |
| CVE-2022-23668 | MEDIUM | 4.9 | 0.9% | May 16, 2022 | A remote authenticated server-side request forgery (ssrf) vulnerability was discovered in Aruba ClearPass Policy Manager... |
| CVE-2022-23659 | MEDIUM | 6.1 | 0.5% | May 16, 2022 | A remote reflected cross site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s):... |
| CVE-2022-30126 | MEDIUM | 5.5 | 2.5% | May 16, 2022 | In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lea... |
| CVE-2022-30050 | MEDIUM | 6.1 | 0.7% | May 16, 2022 | Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php. |
| CVE-2022-25169 | MEDIUM | 5.5 | 2.0% | May 16, 2022 | The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on caref... |
| CVE-2022-1728 | MEDIUM | 6.5 | 0.9% | May 16, 2022 | Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2... |
| CVE-2022-1726 | MEDIUM | 5.4 | 0.7% | May 16, 2022 | Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repositor... |
| CVE-2022-1560 | MEDIUM | 6.5 | 2.2% | May 16, 2022 | The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an includ... |
| CVE-2022-1559 | MEDIUM | 4.8 | 1.0% | May 16, 2022 | The Clipr WordPress plugin through 1.2.3 does not sanitise and escape its API Key settings before outputting it in an at... |
| CVE-2022-1557 | MEDIUM | 5.4 | 1.1% | May 16, 2022 | The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating... |
| CVE-2022-1553 | MEDIUM | 4.9 | 1.2% | May 16, 2022 | Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to... |
| CVE-2022-1512 | MEDIUM | 4.8 | 0.6% | May 16, 2022 | The ScrollReveal.js Effects WordPress plugin through 1.2 does not sanitise and escape its settings, which could allow hi... |
| CVE-2022-1465 | MEDIUM | 6.1 | 0.8% | May 16, 2022 | The WPC Smart Wishlist for WooCommerce WordPress plugin before 2.9.9 does not sanitise and escape a parameter before out... |
| CVE-2022-1455 | MEDIUM | 6.1 | 0.8% | May 16, 2022 | The Call Now Button WordPress plugin before 1.1.2 does not escape a parameter before outputting it back in an attribute ... |
| CVE-2022-1436 | MEDIUM | 6.1 | 0.8% | May 16, 2022 | The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitise and escape the wpcargo_tracking_number paramet... |
| CVE-2022-1435 | MEDIUM | 4.8 | 0.6% | May 16, 2022 | The WPCargo Track & Trace WordPress plugin before 6.9.5 does not sanitize and escapes some of its settings, which could ... |
| CVE-2022-1425 | MEDIUM | 4.3 | 0.8% | May 16, 2022 | The WPQA Builder Plugin WordPress plugin before 5.2, used as a companion plugin for the Discy and Himer , does not valid... |
| CVE-2022-1418 | MEDIUM | 6.1 | 0.4% | May 16, 2022 | The Social Stickers WordPress plugin through 2.2.9 does not have CSRF checks in place when updating its Social Network s... |
| CVE-2022-1408 | MEDIUM | 4.8 | 0.6% | May 16, 2022 | The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not escape various settings before outputti... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now