2022 CVE Vulnerabilities

27,528 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-20642MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,...
CVE-2022-20641MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,...
CVE-2022-20640MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,...
CVE-2022-20639MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,...
CVE-2022-20638MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,...
CVE-2022-20637MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,...
CVE-2022-20636MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,...
CVE-2022-20635MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,...
CVE-2022-0178MEDIUM5.4Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8.
CVE-2022-21682MEDIUM6.5Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of...
CVE-2022-21678MEDIUM4.3Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8...
CVE-2022-22125MEDIUM4.8In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article tag. An ...
CVE-2022-22124MEDIUM5.4In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. A...
CVE-2022-22123MEDIUM5.4In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. A...
CVE-2022-23134MEDIUM5.3After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by una...
CVE-2022-23133MEDIUM5.4An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for othe...
CVE-2022-22112MEDIUM5.4In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CST...
CVE-2022-23115MEDIUM5.4Cross-site request forgery (CSRF) vulnerabilities in Jenkins batch task Plugin 1.19 and earlier allows attackers with Ov...
CVE-2022-23113MEDIUM4.3Jenkins Publish Over SSH Plugin 1.22 and earlier performs a validation of the file name specifying whether it is present...
CVE-2022-23112MEDIUM6.5A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access...
CVE-2022-23111MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers t...
CVE-2022-23110MEDIUM4.8Jenkins Publish Over SSH Plugin 1.22 and earlier does not escape the SSH server name, resulting in a stored cross-site s...
CVE-2022-23109MEDIUM6.5Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline s...
CVE-2022-23108MEDIUM5.4Jenkins Badge Plugin 1.9 and earlier does not escape the description and does not check for allowed protocols when creat...
CVE-2022-23106MEDIUM5.3Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an au...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now