2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36885MEDIUM5.3Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided...
CVE-2022-36884MEDIUM5.3The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the ex...
CVE-2022-36883HIGH7.5A missing permission check in Jenkins Git Plugin 4.11.3 and earlier allows unauthenticated attackers to trigger builds o...
CVE-2022-36882HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Git Plugin 4.11.3 and earlier allows attackers to trigger b...
CVE-2022-36881HIGH8.1Jenkins Git client Plugin 3.11.0 and earlier does not perform SSH host key verification when connecting to Git repositor...
CVE-2022-2550HIGH8.8OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.
CVE-2022-2549MEDIUM5.5NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV.
CVE-2022-35291HIGH8.1Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to p...
CVE-2022-34551MEDIUM6.5Sims v1.0 was discovered to allow path traversal when downloading attachments.
CVE-2022-34550MEDIUM5.4Sims v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /addNotifyServlet. This...
CVE-2022-34549HIGH8.8Sims v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /uploadServlet. This vulner...
CVE-2022-34529MEDIUM5.5WASM3 v0.5.0 was discovered to contain a segmentation fault via the component Compile_Memory_CopyFill.
CVE-2022-33970HIGH7.2Authenticated WordPress Options Change vulnerability in Biplob018 Shortcode Addons plugin <= 3.1.2 at WordPress.
CVE-2022-24406MEDIUM6.5OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to inj...
CVE-2022-24405CRITICAL9.8OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
CVE-2022-23101MEDIUM6.1OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message.
CVE-2022-23100CRITICAL9.8OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).
CVE-2022-23099MEDIUM5.4OX App Suite through 7.10.6 allows XSS by forcing block-wise read.
CVE-2022-2313HIGH7.3A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute ...
CVE-2022-2310CRITICAL9.8An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x p...
CVE-2022-27610HIGH8.1Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno...
CVE-2022-36880MEDIUM6.1The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message.
CVE-2022-36879MEDIUM5.5An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a ...
CVE-2022-34971HIGH8.8An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to exec...
CVE-2022-34612MEDIUM5.5Rizin v0.4.0 and below was discovered to contain an integer overflow via the function get_long_object(). This vulnerabil...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now