2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2805MEDIUM6.5A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-sty...
CVE-2022-23241HIGH8.1Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerabi...
CVE-2022-1970Rejected reason: The originally reported issue in https://github.com/syedsohaibkarim/OpenRedirect-Keycloak18.0.0 is a kn...
CVE-2022-1738HIGH7.5Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to an out-of-bounds read, which could allow an attacker to...
CVE-2022-1523CRITICAL9.1Fuji Electric D300win prior to version 3.7.1.17 is vulnerable to a write-what-where condition, which could allow an atta...
CVE-2022-1414HIGH8.83scale API Management 2 does not perform adequate sanitation for user input in multiple fields. An authenticated user co...
CVE-2022-41709HIGH7.8Markdownify version 1.4.1 allows an external attacker to execute arbitrary code remotely on any client attempting to vie...
CVE-2022-41707MEDIUM6.5Relatedcode's Messenger version 7bcd20b allows an authenticated external attacker to access sensitive data of any user o...
CVE-2022-43435MEDIUM5.3Jenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-gene...
CVE-2022-43434MEDIUM5.3Jenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protec...
CVE-2022-43433MEDIUM4.3Jenkins ScreenRecorder Plugin 0.7 and earlier programmatically disables Content-Security-Policy protection for user-gene...
CVE-2022-43432MEDIUM4.3Jenkins XFramium Builder Plugin 1.0.22 and earlier programmatically disables Content-Security-Policy protection for user...
CVE-2022-43431MEDIUM4.3Jenkins Compuware Strobe Measurement Plugin 1.0.1 and earlier does not perform a permission check in an HTTP endpoint, a...
CVE-2022-43430HIGH7.5Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML externa...
CVE-2022-43429HIGH7.5Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not lim...
CVE-2022-43428MEDIUM5.3Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier implements an agent/controller message that does not lim...
CVE-2022-43427MEDIUM4.3Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpo...
CVE-2022-43426MEDIUM5.3Jenkins S3 Explorer Plugin 1.0.8 and earlier does not mask the AWS_SECRET_ACCESS_KEY form field, increasing the potentia...
CVE-2022-43425MEDIUM5.4Jenkins Custom Checkbox Parameter Plugin 1.4 and earlier does not escape the name and description of Custom Checkbox Par...
CVE-2022-43424MEDIUM5.3Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not l...
CVE-2022-43423MEDIUM5.3Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier implements an agent/controll...
CVE-2022-43422MEDIUM5.3Jenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier implements an agent/controller message that does not limit wh...
CVE-2022-43421MEDIUM5.3A missing permission check in Jenkins Tuleap Git Branch Source Plugin 3.2.4 and earlier allows unauthenticated attackers...
CVE-2022-43420MEDIUM5.4Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast ...
CVE-2022-43419MEDIUM6.5Jenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now