2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2183 | HIGH | 7.8 | 1.5% | Jun 23, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-2182 | HIGH | 7.8 | 1.5% | Jun 23, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
| CVE-2022-26864 | HIGH | 7.8 | 0.3% | Jun 23, 2022 | Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potenti... |
| CVE-2022-26863 | HIGH | 7.8 | 0.3% | Jun 23, 2022 | Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potenti... |
| CVE-2022-26862 | HIGH | 7.8 | 0.3% | Jun 23, 2022 | Prior Dell BIOS versions contain an Input Validation vulnerability. A locally authenticated malicious user could potenti... |
| CVE-2022-34328 | MEDIUM | 6.1 | 2.2% | Jun 23, 2022 | PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php. |
| CVE-2022-34300 | HIGH | 8.8 | 1.4% | Jun 23, 2022 | In tinyexr 1.0.1, there is a heap-based buffer over-read in tinyexr::DecodePixelData. |
| CVE-2022-34299 | HIGH | 8.1 | 1.1% | Jun 23, 2022 | There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b. |
| CVE-2022-34298 | MEDIUM | 5.3 | 3.1% | Jun 23, 2022 | The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack." |
| CVE-2022-34296 | HIGH | 7.5 | 1.1% | Jun 23, 2022 | In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request. |
| CVE-2022-34295 | MEDIUM | 6.5 | 1.5% | Jun 23, 2022 | totd before 1.5.3 does not properly randomize mesg IDs. |
| CVE-2022-34213 | MEDIUM | 6.5 | 0.7% | Jun 23, 2022 | Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configu... |
| CVE-2022-34212 | MEDIUM | 5.7 | 0.6% | Jun 23, 2022 | A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read pe... |
| CVE-2022-34211 | MEDIUM | 6.5 | 0.5% | Jun 23, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attacke... |
| CVE-2022-34210 | MEDIUM | 6.5 | 0.6% | Jun 23, 2022 | A missing permission check in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers with Overall/Read permission t... |
| CVE-2022-34209 | MEDIUM | 6.5 | 0.6% | Jun 23, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers to conn... |
| CVE-2022-34208 | MEDIUM | 4.3 | 0.6% | Jun 23, 2022 | A missing permission check in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers with Overall/Read permissi... |
| CVE-2022-34207 | MEDIUM | 6.5 | 0.5% | Jun 23, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to ... |
| CVE-2022-34206 | MEDIUM | 4.3 | 0.5% | Jun 23, 2022 | A missing permission check in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers with Overall/Read pe... |
| CVE-2022-34205 | MEDIUM | 6.5 | 0.5% | Jun 23, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attacke... |
| CVE-2022-34204 | MEDIUM | 4.3 | 0.5% | Jun 23, 2022 | A missing permission check in Jenkins EasyQA Plugin 1.0 and earlier allows attackers with Overall/Read permission to con... |
| CVE-2022-34203 | HIGH | 8.8 | 0.5% | Jun 23, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins EasyQA Plugin 1.0 and earlier allows attackers to connect t... |
| CVE-2022-34202 | MEDIUM | 6.5 | 0.6% | Jun 23, 2022 | Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins ... |
| CVE-2022-34201 | MEDIUM | 6.5 | 0.6% | Jun 23, 2022 | A missing permission check in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers with Overall/Re... |
| CVE-2022-34200 | HIGH | 8.8 | 0.5% | Jun 23, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows at... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now