2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29799MEDIUM5.5A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the Operational...
CVE-2022-23952HIGH7.5In Keylime before 6.3.0, current keylime installer installs the keylime.conf file, which can contain sensitive data, as ...
CVE-2022-23951MEDIUM5.5In Keylime before 6.3.0, quote responses from the agent can contain possibly untrusted ZIP data which can lead to zip bo...
CVE-2022-23950HIGH7.5In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged ...
CVE-2022-23949HIGH7.5In Keylime before 6.3.0, unsanitized UUIDs can be passed by a rogue agent and can lead to log spoofing on the verifier a...
CVE-2022-23948HIGH7.5A flaw was found in Keylime before 6.3.0. The logic in the Keylime agent for checking for a secure mount can be fooled b...
CVE-2022-40030CRITICAL9.8SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId p...
CVE-2022-40029MEDIUM4.8SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via...
CVE-2022-40028MEDIUM4.8SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via...
CVE-2022-40027MEDIUM6.1SourceCodester Simple Task Managing System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via...
CVE-2022-40026HIGH7.2SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId p...
CVE-2022-31679LOW3.7Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3....
CVE-2022-30578CRITICAL9The Web Server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that al...
CVE-2022-30577CRITICAL9The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a l...
CVE-2022-40616HIGH8.1IBM Maximo Asset Management 7.6.1.1, 7.6.1.2, and 7.6.1.3 could allow a user to bypass authentication and obtain sensiti...
CVE-2022-3251MEDIUM5.3Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/minarca prior to 4.2.2.
CVE-2022-3250MEDIUM5.3Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository ikus060/rdiffweb prior to 2.4.6.
CVE-2022-37027HIGH7.2Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can...
CVE-2022-41255MEDIUM6.5Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins con...
CVE-2022-41254MEDIUM6.5Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allow attackers with Overall/Read permission to co...
CVE-2022-41253HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins CONS3RT Plugin 1.0.0 and earlier allows attackers to connec...
CVE-2022-41252MEDIUM4.3Missing permission checks in Jenkins CONS3RT Plugin 1.0.0 and earlier allows users with Overall/Read permission to enume...
CVE-2022-41251MEDIUM4.3A missing permission check in Jenkins Apprenda Plugin 2.2.0 and earlier allows users with Overall/Read permission to enu...
CVE-2022-41250MEDIUM6.5A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permissio...
CVE-2022-41249HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers to c...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now