2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26947 | MEDIUM | 5.4 | 0.6% | Mar 30, 2022 | Archer 6.x through 6.9 SP3 (6.9.3.0) contains a reflected XSS vulnerability. A remote authenticated malicious Archer use... |
| CVE-2022-26244 | MEDIUM | 5.4 | 0.5% | Mar 30, 2022 | A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to ... |
| CVE-2022-22948 | MEDIUM | 6.5 | 13.9% | Mar 29, 2022 | The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious act... |
| CVE-2022-1122 | MEDIUM | 5.5 | 1.1% | Mar 29, 2022 | A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large... |
| CVE-2022-28160 | MEDIUM | 6.5 | 1.1% | Mar 29, 2022 | Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on t... |
| CVE-2022-28159 | MEDIUM | 5.4 | 0.8% | Mar 29, 2022 | Jenkins Tests Selector Plugin 1.3.3 and earlier does not escape the Properties File Path option for Choosing Tests param... |
| CVE-2022-28158 | MEDIUM | 6.5 | 0.7% | Mar 29, 2022 | A missing permission check in Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Overall/Re... |
| CVE-2022-28157 | MEDIUM | 6.5 | 1.4% | Mar 29, 2022 | Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to upload arbi... |
| CVE-2022-28156 | MEDIUM | 6.5 | 1.5% | Mar 29, 2022 | Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to copy arbitr... |
| CVE-2022-28153 | MEDIUM | 5.4 | 0.8% | Mar 29, 2022 | Jenkins SiteMonitor Plugin 0.6 and earlier does not escape URLs of sites to monitor in tooltips, resulting in a stored c... |
| CVE-2022-28152 | MEDIUM | 4.3 | 0.6% | Mar 29, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows att... |
| CVE-2022-28151 | MEDIUM | 4.3 | 0.7% | Mar 29, 2022 | A missing permission check in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers with Item/Read p... |
| CVE-2022-28149 | MEDIUM | 5.4 | 0.8% | Mar 29, 2022 | Jenkins Job and Node ownership Plugin 0.13.0 and earlier does not escape the names of the secondary owners, resulting in... |
| CVE-2022-28148 | MEDIUM | 6.5 | 1.8% | Mar 29, 2022 | The file browser in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier may interpret some paths to fil... |
| CVE-2022-28147 | MEDIUM | 4.3 | 0.7% | Mar 29, 2022 | A missing permission check in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with... |
| CVE-2022-28146 | MEDIUM | 6.5 | 1.8% | Mar 29, 2022 | Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Item/Configure permission to ... |
| CVE-2022-28145 | MEDIUM | 5.4 | 0.8% | Mar 29, 2022 | Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier does not apply Content-Security-Policy headers to r... |
| CVE-2022-28144 | MEDIUM | 6.5 | 0.8% | Mar 29, 2022 | Jenkins Proxmox Plugin 0.7.0 and earlier does not perform a permission check in several HTTP endpoints, allowing attacke... |
| CVE-2022-28143 | MEDIUM | 6.5 | 0.5% | Mar 29, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Proxmox Plugin 0.7.0 and earlier allows attackers to connec... |
| CVE-2022-28141 | MEDIUM | 6.5 | 0.9% | Mar 29, 2022 | Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the global config.xml fil... |
| CVE-2022-28139 | MEDIUM | 4.3 | 0.7% | Mar 29, 2022 | A missing permission check in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers with Overall/Read p... |
| CVE-2022-28138 | MEDIUM | 4.3 | 0.6% | Mar 29, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attack... |
| CVE-2022-28137 | MEDIUM | 4.3 | 0.7% | Mar 29, 2022 | A missing permission check in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers with ... |
| CVE-2022-28135 | MEDIUM | 6.5 | 0.9% | Mar 29, 2022 | Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configurati... |
| CVE-2022-28134 | MEDIUM | 5.4 | 0.6% | Mar 29, 2022 | Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoin... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now