2022 CVE Vulnerabilities
27,528 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20642 | MEDIUM | 6.1 | 0.8% | Jan 14, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,... |
| CVE-2022-20641 | MEDIUM | 6.1 | 0.8% | Jan 14, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,... |
| CVE-2022-20640 | MEDIUM | 6.1 | 0.8% | Jan 14, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,... |
| CVE-2022-20639 | MEDIUM | 6.1 | 0.8% | Jan 14, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,... |
| CVE-2022-20638 | MEDIUM | 6.1 | 0.8% | Jan 14, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,... |
| CVE-2022-20637 | MEDIUM | 6.1 | 0.8% | Jan 14, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,... |
| CVE-2022-20636 | MEDIUM | 6.1 | 0.8% | Jan 14, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,... |
| CVE-2022-20635 | MEDIUM | 6.1 | 0.8% | Jan 14, 2022 | Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated,... |
| CVE-2022-0178 | MEDIUM | 5.4 | 0.7% | Jan 13, 2022 | Missing Authorization vulnerability in snipe snipe/snipe-it.This issue affects snipe/snipe-i before 5.3.8. |
| CVE-2022-21682 | MEDIUM | 6.5 | 1.7% | Jan 13, 2022 | Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of... |
| CVE-2022-21678 | MEDIUM | 4.3 | 0.9% | Jan 13, 2022 | Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8... |
| CVE-2022-22125 | MEDIUM | 4.8 | 0.8% | Jan 13, 2022 | In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article tag. An ... |
| CVE-2022-22124 | MEDIUM | 5.4 | 0.7% | Jan 13, 2022 | In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. A... |
| CVE-2022-22123 | MEDIUM | 5.4 | 0.7% | Jan 13, 2022 | In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. A... |
| CVE-2022-23134 | MEDIUM | 5.3 | 84.7% | Jan 13, 2022 | After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by una... |
| CVE-2022-23133 | MEDIUM | 5.4 | 1.0% | Jan 13, 2022 | An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for othe... |
| CVE-2022-22112 | MEDIUM | 5.4 | 0.6% | Jan 13, 2022 | In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CST... |
| CVE-2022-23115 | MEDIUM | 5.4 | 0.6% | Jan 12, 2022 | Cross-site request forgery (CSRF) vulnerabilities in Jenkins batch task Plugin 1.19 and earlier allows attackers with Ov... |
| CVE-2022-23113 | MEDIUM | 4.3 | 1.5% | Jan 12, 2022 | Jenkins Publish Over SSH Plugin 1.22 and earlier performs a validation of the file name specifying whether it is present... |
| CVE-2022-23112 | MEDIUM | 6.5 | 0.9% | Jan 12, 2022 | A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access... |
| CVE-2022-23111 | MEDIUM | 4.3 | 27.6% | Jan 12, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers t... |
| CVE-2022-23110 | MEDIUM | 4.8 | 0.8% | Jan 12, 2022 | Jenkins Publish Over SSH Plugin 1.22 and earlier does not escape the SSH server name, resulting in a stored cross-site s... |
| CVE-2022-23109 | MEDIUM | 6.5 | 1.0% | Jan 12, 2022 | Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline s... |
| CVE-2022-23108 | MEDIUM | 5.4 | 0.8% | Jan 12, 2022 | Jenkins Badge Plugin 1.9 and earlier does not escape the description and does not check for allowed protocols when creat... |
| CVE-2022-23106 | MEDIUM | 5.3 | 1.1% | Jan 12, 2022 | Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an au... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now