2022 CVE Vulnerabilities
27,541 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36885 | MEDIUM | 5.3 | 0.7% | Jul 27, 2022 | Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided... |
| CVE-2022-36884 | MEDIUM | 5.3 | 0.8% | Jul 27, 2022 | The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the ex... |
| CVE-2022-36883 | HIGH | 7.5 | 5.5% | Jul 27, 2022 | A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds o... |
| CVE-2022-36882 | HIGH | 8.8 | 0.6% | Jul 27, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger b... |
| CVE-2022-36881 | HIGH | 8.1 | 0.8% | Jul 27, 2022 | Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositor... |
| CVE-2022-2550 | HIGH | 8.8 | 47.5% | Jul 27, 2022 | OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5. |
| CVE-2022-2549 | MEDIUM | 5.5 | 0.5% | Jul 27, 2022 | NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV. |
| CVE-2022-35291 | HIGH | 8.1 | 0.6% | Jul 27, 2022 | Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to p... |
| CVE-2022-34551 | MEDIUM | 6.5 | 0.8% | Jul 27, 2022 | Sims v1.0 was discovered to allow path traversal when downloading attachments. |
| CVE-2022-34550 | MEDIUM | 5.4 | 0.4% | Jul 27, 2022 | Sims v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /addNotifyServlet. This... |
| CVE-2022-34549 | HIGH | 8.8 | 1.1% | Jul 27, 2022 | Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulner... |
| CVE-2022-34529 | MEDIUM | 5.5 | 0.3% | Jul 27, 2022 | WASM3 v0.5.0 was discovered to contain a segmentation fault via the component Compile_Memory_CopyFill. |
| CVE-2022-33970 | HIGH | 7.2 | 0.9% | Jul 27, 2022 | Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress. |
| CVE-2022-24406 | MEDIUM | 6.5 | 0.8% | Jul 27, 2022 | OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to inj... |
| CVE-2022-24405 | CRITICAL | 9.8 | 3.1% | Jul 27, 2022 | OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API. |
| CVE-2022-23101 | MEDIUM | 6.1 | 0.6% | Jul 27, 2022 | OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message. |
| CVE-2022-23100 | CRITICAL | 9.8 | 3.0% | Jul 27, 2022 | OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment). |
| CVE-2022-23099 | MEDIUM | 5.4 | 0.6% | Jul 27, 2022 | OX App Suite through 7.10.6 allows XSS by forcing block-wise read. |
| CVE-2022-2313 | HIGH | 7.3 | 0.3% | Jul 27, 2022 | A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute ... |
| CVE-2022-2310 | CRITICAL | 9.8 | 1.0% | Jul 27, 2022 | An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x p... |
| CVE-2022-27610 | HIGH | 8.1 | 1.3% | Jul 27, 2022 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno... |
| CVE-2022-36880 | MEDIUM | 6.1 | 0.5% | Jul 27, 2022 | The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message. |
| CVE-2022-36879 | MEDIUM | 5.5 | 0.3% | Jul 27, 2022 | An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a ... |
| CVE-2022-34971 | HIGH | 8.8 | 1.0% | Jul 27, 2022 | An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to exec... |
| CVE-2022-34612 | MEDIUM | 5.5 | 0.4% | Jul 27, 2022 | Rizin v0.4.0 and below was discovered to contain an integer overflow via the function get_long_object(). This vulnerabil... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now