2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-45384MEDIUM6.5Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xm...
CVE-2022-45383MEDIUM6.5An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Supp...
CVE-2022-45382MEDIUM5.4Jenkins Naginator Plugin 1.18.1 and earlier does not escape display names of source builds in builds that were triggered...
CVE-2022-45381HIGH8.1Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and b...
CVE-2022-45380MEDIUM5.4Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in a...
CVE-2022-45379HIGH7.5Jenkins Script Security Plugin 1189.vb_a_b_7c8fd5fde and earlier stores whole-script approvals as the SHA-1 hash of the ...
CVE-2022-38666HIGH7.5Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificat...
CVE-2022-27895HIGH7.5Information Exposure Through Log Files vulnerability discovered in Foundry when logs were captured using an underlying l...
CVE-2022-41558MEDIUM5.4The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analyst, TIBCO Spotfire Ana...
CVE-2022-43071MEDIUM5.5A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial o...
CVE-2022-3998CRITICAL9.8A vulnerability, which was classified as critical, was found in MonikaBrzica scm. This affects an unknown part of the fi...
CVE-2022-3997MEDIUM6.1A vulnerability, which was classified as critical, has been found in MonikaBrzica scm. Affected by this issue is some un...
CVE-2022-42001MEDIUM5.4Cross-site Scripting (XSS) vulnerability in BlueSpiceBookshelf extension of BlueSpice allows user with regular account a...
CVE-2022-42000MEDIUM5.4Cross-site Scripting (XSS) vulnerability in BlueSpiceSocialProfile extension of BlueSpice allows user with comment permi...
CVE-2022-41814MEDIUM5.4Cross-site Scripting (XSS) vulnerability in BlueSpiceFoundation extension of BlueSpice allows user with regular account ...
CVE-2022-41789MEDIUM5.4Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows logged in user with edit permiss...
CVE-2022-41611MEDIUM4.8Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows user with admin privileges to in...
CVE-2022-3958MEDIUM5.4Cross-site Scripting (XSS) vulnerability in BlueSpiceUserSidebar extension of BlueSpice allows user with regular account...
CVE-2022-3895MEDIUM6.1Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output...
CVE-2022-3893MEDIUM4.8Cross-site Scripting (XSS) vulnerability in BlueSpiceCustomMenu extension of BlueSpice allows user with admin permission...
CVE-2022-3240HIGH8.8The "Follow Me Plugin" plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including...
CVE-2022-40309MEDIUM4.3Users with write permissions to a repository can delete arbitrary directories.
CVE-2022-40308HIGH7.5If anonymous read enabled, it's possible to read the database file directly without logging in.
CVE-2022-3737HIGH7.8In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to ...
CVE-2022-3480HIGH7.5A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices be...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now