2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-45384 | MEDIUM | 6.5 | 0.6% | Nov 15, 2022 | Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xm... |
| CVE-2022-45383 | MEDIUM | 6.5 | 0.6% | Nov 15, 2022 | An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Supp... |
| CVE-2022-45382 | MEDIUM | 5.4 | 0.6% | Nov 15, 2022 | Jenkins Naginator Plugin 1.18.1 and earlier does not escape display names of source builds in builds that were triggered... |
| CVE-2022-45381 | HIGH | 8.1 | 1.3% | Nov 15, 2022 | Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and b... |
| CVE-2022-45380 | MEDIUM | 5.4 | 0.6% | Nov 15, 2022 | Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in a... |
| CVE-2022-45379 | HIGH | 7.5 | 0.5% | Nov 15, 2022 | Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the ... |
| CVE-2022-38666 | HIGH | 7.5 | 0.4% | Nov 15, 2022 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificat... |
| CVE-2022-27895 | HIGH | 7.5 | 0.4% | Nov 15, 2022 | Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying l... |
| CVE-2022-41558 | MEDIUM | 5.4 | 0.5% | Nov 15, 2022 | The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Ana... |
| CVE-2022-43071 | MEDIUM | 5.5 | 0.3% | Nov 15, 2022 | A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial o... |
| CVE-2022-3998 | CRITICAL | 9.8 | 0.5% | Nov 15, 2022 | A vulnerability, which was classified as critical, was found in MonikaBrzica scm. This affects an unknown part of the fi... |
| CVE-2022-3997 | MEDIUM | 6.1 | 0.4% | Nov 15, 2022 | A vulnerability, which was classified as critical, has been found in MonikaBrzica scm. Affected by this issue is some un... |
| CVE-2022-42001 | MEDIUM | 5.4 | 0.3% | Nov 15, 2022 | Cross-site Scripting (XSS) vulnerability in BlueSpiceBookshelf extension of BlueSpice allows user with regular account a... |
| CVE-2022-42000 | MEDIUM | 5.4 | 0.3% | Nov 15, 2022 | Cross-site Scripting (XSS) vulnerability in BlueSpiceSocialProfile extension of BlueSpice allows user with comment permi... |
| CVE-2022-41814 | MEDIUM | 5.4 | 0.3% | Nov 15, 2022 | Cross-site Scripting (XSS) vulnerability in BlueSpiceFoundation extension of BlueSpice allows user with regular account ... |
| CVE-2022-41789 | MEDIUM | 5.4 | 0.3% | Nov 15, 2022 | Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows logged in user with edit permiss... |
| CVE-2022-41611 | MEDIUM | 4.8 | 0.3% | Nov 15, 2022 | Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows user with admin privileges to in... |
| CVE-2022-3958 | MEDIUM | 5.4 | 0.3% | Nov 15, 2022 | Cross-site Scripting (XSS) vulnerability in BlueSpiceUserSidebar extension of BlueSpice allows user with regular account... |
| CVE-2022-3895 | MEDIUM | 6.1 | 0.3% | Nov 15, 2022 | Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output... |
| CVE-2022-3893 | MEDIUM | 4.8 | 0.3% | Nov 15, 2022 | Cross-site Scripting (XSS) vulnerability in BlueSpiceCustomMenu extension of BlueSpice allows user with admin permission... |
| CVE-2022-3240 | HIGH | 8.8 | 0.6% | Nov 15, 2022 | The "Follow Me Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including... |
| CVE-2022-40309 | MEDIUM | 4.3 | 1.4% | Nov 15, 2022 | Users with write permissions to a repository can delete arbitrary directories. |
| CVE-2022-40308 | HIGH | 7.5 | 1.2% | Nov 15, 2022 | If anonymous read enabled, it's possible to read the database file directly without logging in. |
| CVE-2022-3737 | HIGH | 7.8 | 0.2% | Nov 15, 2022 | In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to ... |
| CVE-2022-3480 | HIGH | 7.5 | 0.9% | Nov 15, 2022 | A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices be... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now