2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29799 | MEDIUM | 5.5 | 11.7% | Sep 21, 2022 | A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the Operational... |
| CVE-2022-23952 | HIGH | 7.5 | 1.1% | Sep 21, 2022 | In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as ... |
| CVE-2022-23951 | MEDIUM | 5.5 | 0.4% | Sep 21, 2022 | In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bo... |
| CVE-2022-23950 | HIGH | 7.5 | 1.2% | Sep 21, 2022 | In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged ... |
| CVE-2022-23949 | HIGH | 7.5 | 1.0% | Sep 21, 2022 | In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier a... |
| CVE-2022-23948 | HIGH | 7.5 | 1.1% | Sep 21, 2022 | A flaw was found in Keylime before 6.3.0. The logic in the Keylime agent for checking for a secure mount can be fooled b... |
| CVE-2022-40030 | CRITICAL | 9.8 | 1.2% | Sep 21, 2022 | SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId p... |
| CVE-2022-40029 | MEDIUM | 4.8 | 0.6% | Sep 21, 2022 | SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via... |
| CVE-2022-40028 | MEDIUM | 4.8 | 0.6% | Sep 21, 2022 | SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via... |
| CVE-2022-40027 | MEDIUM | 6.1 | 0.7% | Sep 21, 2022 | SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via... |
| CVE-2022-40026 | HIGH | 7.2 | 0.7% | Sep 21, 2022 | SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId p... |
| CVE-2022-31679 | LOW | 3.7 | 0.5% | Sep 21, 2022 | Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.... |
| CVE-2022-30578 | CRITICAL | 9 | 0.8% | Sep 21, 2022 | The Web Server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that al... |
| CVE-2022-30577 | CRITICAL | 9 | 0.7% | Sep 21, 2022 | The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a l... |
| CVE-2022-40616 | HIGH | 8.1 | 0.5% | Sep 21, 2022 | IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensiti... |
| CVE-2022-3251 | MEDIUM | 5.3 | 0.5% | Sep 21, 2022 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2. |
| CVE-2022-3250 | MEDIUM | 5.3 | 0.4% | Sep 21, 2022 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6. |
| CVE-2022-37027 | HIGH | 7.2 | 20.8% | Sep 21, 2022 | Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can... |
| CVE-2022-41255 | MEDIUM | 6.5 | 0.7% | Sep 21, 2022 | Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins con... |
| CVE-2022-41254 | MEDIUM | 6.5 | 0.7% | Sep 21, 2022 | Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to co... |
| CVE-2022-41253 | HIGH | 8.8 | 0.5% | Sep 21, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins CONS3RT Plugin 1.0.0 and earlier allows attackers to connec... |
| CVE-2022-41252 | MEDIUM | 4.3 | 0.5% | Sep 21, 2022 | Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enume... |
| CVE-2022-41251 | MEDIUM | 4.3 | 0.5% | Sep 21, 2022 | A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier allows users with Overall/Read permission to enu... |
| CVE-2022-41250 | MEDIUM | 6.5 | 0.5% | Sep 21, 2022 | A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permissio... |
| CVE-2022-41249 | HIGH | 8.8 | 0.4% | Sep 21, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers to c... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now