2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2805 | MEDIUM | 6.5 | 0.4% | Oct 19, 2022 | A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-sty... |
| CVE-2022-23241 | HIGH | 8.1 | 0.7% | Oct 19, 2022 | Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerabi... |
| CVE-2022-1970 | — | — | — | Oct 19, 2022 | Rejected reason: The originally reported issue in https://github.com/syedsohaibkarim/OpenRedirect-Keycloak18.0.0 is a kn... |
| CVE-2022-1738 | HIGH | 7.5 | 0.5% | Oct 19, 2022 | Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to an out-of-bounds read, which could allow an attacker to... |
| CVE-2022-1523 | CRITICAL | 9.1 | 0.5% | Oct 19, 2022 | Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to a write-what-where condition, which could allow an atta... |
| CVE-2022-1414 | HIGH | 8.8 | 0.8% | Oct 19, 2022 | 3scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user co... |
| CVE-2022-41709 | HIGH | 7.8 | 0.4% | Oct 19, 2022 | Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to vie... |
| CVE-2022-41707 | MEDIUM | 6.5 | 0.8% | Oct 19, 2022 | Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access sensitive data of any user o... |
| CVE-2022-43435 | MEDIUM | 5.3 | 0.6% | Oct 19, 2022 | Jenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-gene... |
| CVE-2022-43434 | MEDIUM | 5.3 | 0.6% | Oct 19, 2022 | Jenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protec... |
| CVE-2022-43433 | MEDIUM | 4.3 | 0.5% | Oct 19, 2022 | Jenkins ScreenRecorder Plugin 0.7 and earlier programmatically disables Content-Security-Policy protection for user-gene... |
| CVE-2022-43432 | MEDIUM | 4.3 | 0.5% | Oct 19, 2022 | Jenkins XFramium Builder Plugin 1.0.22 and earlier programmatically disables Content-Security-Policy protection for user... |
| CVE-2022-43431 | MEDIUM | 4.3 | 0.4% | Oct 19, 2022 | Jenkins Compuware Strobe Measurement Plugin 1.0.1 and earlier does not perform a permission check in an HTTP endpoint, a... |
| CVE-2022-43430 | HIGH | 7.5 | 0.7% | Oct 19, 2022 | Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML externa... |
| CVE-2022-43429 | HIGH | 7.5 | 0.6% | Oct 19, 2022 | Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not lim... |
| CVE-2022-43428 | MEDIUM | 5.3 | 0.6% | Oct 19, 2022 | Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not lim... |
| CVE-2022-43427 | MEDIUM | 4.3 | 0.5% | Oct 19, 2022 | Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpo... |
| CVE-2022-43426 | MEDIUM | 5.3 | 0.5% | Oct 19, 2022 | Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potentia... |
| CVE-2022-43425 | MEDIUM | 5.4 | 0.8% | Oct 19, 2022 | Jenkins Custom Checkbox Parameter Plugin 1.4 and earlier does not escape the name and description of Custom Checkbox Par... |
| CVE-2022-43424 | MEDIUM | 5.3 | 0.6% | Oct 19, 2022 | Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not l... |
| CVE-2022-43423 | MEDIUM | 5.3 | 0.6% | Oct 19, 2022 | Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier implements an agent/controll... |
| CVE-2022-43422 | MEDIUM | 5.3 | 0.7% | Oct 19, 2022 | Jenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier implements an agent/controller message that does not limit wh... |
| CVE-2022-43421 | MEDIUM | 5.3 | 0.7% | Oct 19, 2022 | A missing permission check in Jenkins Tuleap Git Branch Source Plugin 3.2.4 and earlier allows unauthenticated attackers... |
| CVE-2022-43420 | MEDIUM | 5.4 | 0.6% | Oct 19, 2022 | Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast ... |
| CVE-2022-43419 | MEDIUM | 6.5 | 0.7% | Oct 19, 2022 | Jenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now