2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-26947MEDIUM5.4Archer 6.x through 6.9 SP3 (6.9.3.0) contains a reflected XSS vulnerability. A remote authenticated malicious Archer use...
CVE-2022-26244MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to ...
CVE-2022-22948MEDIUM6.5The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious act...
CVE-2022-1122MEDIUM5.5A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large...
CVE-2022-28160MEDIUM6.5Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on t...
CVE-2022-28159MEDIUM5.4Jenkins Tests Selector Plugin 1.3.3 and earlier does not escape the Properties File Path option for Choosing Tests param...
CVE-2022-28158MEDIUM6.5A missing permission check in Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Overall/Re...
CVE-2022-28157MEDIUM6.5Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to upload arbi...
CVE-2022-28156MEDIUM6.5Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to copy arbitr...
CVE-2022-28153MEDIUM5.4Jenkins SiteMonitor Plugin 0.6 and earlier does not escape URLs of sites to monitor in tooltips, resulting in a stored c...
CVE-2022-28152MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows att...
CVE-2022-28151MEDIUM4.3A missing permission check in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers with Item/Read p...
CVE-2022-28149MEDIUM5.4Jenkins Job and Node ownership Plugin 0.13.0 and earlier does not escape the names of the secondary owners, resulting in...
CVE-2022-28148MEDIUM6.5The file browser in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier may interpret some paths to fil...
CVE-2022-28147MEDIUM4.3A missing permission check in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with...
CVE-2022-28146MEDIUM6.5Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Item/Configure permission to ...
CVE-2022-28145MEDIUM5.4Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier does not apply Content-Security-Policy headers to r...
CVE-2022-28144MEDIUM6.5Jenkins Proxmox Plugin 0.7.0 and earlier does not perform a permission check in several HTTP endpoints, allowing attacke...
CVE-2022-28143MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Proxmox Plugin 0.7.0 and earlier allows attackers to connec...
CVE-2022-28141MEDIUM6.5Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the global config.xml fil...
CVE-2022-28139MEDIUM4.3A missing permission check in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers with Overall/Read p...
CVE-2022-28138MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attack...
CVE-2022-28137MEDIUM4.3A missing permission check in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers with ...
CVE-2022-28135MEDIUM6.5Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configurati...
CVE-2022-28134MEDIUM5.4Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoin...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now