2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34174 | HIGH | 7.5 | 1.2% | Jun 23, 2022 | In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows disting... |
| CVE-2022-34173 | MEDIUM | 5.4 | 1.4% | Jun 23, 2022 | In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without esca... |
| CVE-2022-34172 | MEDIUM | 5.4 | 1.4% | Jun 23, 2022 | In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' param... |
| CVE-2022-34171 | MEDIUM | 5.4 | 1.4% | Jun 23, 2022 | In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output gen... |
| CVE-2022-34170 | MEDIUM | 5.4 | 1.4% | Jun 23, 2022 | In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does ... |
| CVE-2022-34013 | MEDIUM | 4.3 | 0.5% | Jun 23, 2022 | OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under... |
| CVE-2022-34012 | MEDIUM | 6.5 | 0.5% | Jun 23, 2022 | Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrato... |
| CVE-2022-34011 | MEDIUM | 4.3 | 0.5% | Jun 23, 2022 | OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls. |
| CVE-2022-33127 | CRITICAL | 9.8 | 1.7% | Jun 23, 2022 | The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a ... |
| CVE-2022-33124 | MEDIUM | 5.5 | 0.7% | Jun 23, 2022 | AIOHTTP 3.8.1 can report a "ValueError: Invalid IPv6 URL" outcome, which can lead to a Denial of Service (DoS). NOTE: mu... |
| CVE-2022-33114 | HIGH | 7.2 | 0.9% | Jun 23, 2022 | Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/syste... |
| CVE-2022-33113 | MEDIUM | 5.4 | 0.5% | Jun 23, 2022 | Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyw... |
| CVE-2022-33105 | HIGH | 7.5 | 3.0% | Jun 23, 2022 | Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID. |
| CVE-2022-33097 | HIGH | 7.5 | 0.9% | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_... |
| CVE-2022-33096 | HIGH | 7.5 | 0.9% | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index. |
| CVE-2022-33095 | HIGH | 7.5 | 1.0% | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resu... |
| CVE-2022-33094 | HIGH | 7.5 | 0.9% | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map. |
| CVE-2022-33093 | HIGH | 7.5 | 0.9% | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list. |
| CVE-2022-33092 | HIGH | 7.5 | 0.9% | Jun 23, 2022 | 74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index. |
| CVE-2022-33070 | MEDIUM | 5.5 | 1.1% | Jun 23, 2022 | Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in proto... |
| CVE-2022-33069 | MEDIUM | 5.5 | 0.6% | Jun 23, 2022 | Ethereum Solidity v0.8.14 contains an assertion failure via SMTEncoder::indexOrMemberAssignment() at SMTEncoder.cpp. |
| CVE-2022-33068 | MEDIUM | 5.5 | 1.1% | Jun 23, 2022 | An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Se... |
| CVE-2022-33067 | MEDIUM | 5.5 | 0.6% | Jun 23, 2022 | Lrzip v0.651 was discovered to contain multiple invalid arithmetic shifts via the functions get_magic in lrzip.c and Pre... |
| CVE-2022-33034 | HIGH | 7.8 | 0.7% | Jun 23, 2022 | LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c. |
| CVE-2022-33033 | HIGH | 7.8 | 0.7% | Jun 23, 2022 | LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now