2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34174HIGH7.5In Jenkins 2.355 and earlier, LTS 2.332.3 and earlier, an observable timing discrepancy on the login form allows disting...
CVE-2022-34173MEDIUM5.4In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without esca...
CVE-2022-34172MEDIUM5.4In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' param...
CVE-2022-34171MEDIUM5.4In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output gen...
CVE-2022-34170MEDIUM5.4In Jenkins 2.320 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the help icon does ...
CVE-2022-34013MEDIUM4.3OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Logo parameter under...
CVE-2022-34012MEDIUM6.5Insecure permissions in OneBlog v2.3.4 allows low-level administrators to reset the passwords of high-level administrato...
CVE-2022-34011MEDIUM4.3OneBlog v2.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the parameter entryUrls.
CVE-2022-33127CRITICAL9.8The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a ...
CVE-2022-33124MEDIUM5.5AIOHTTP 3.8.1 can report a "ValueError: Invalid IPv6 URL" outcome, which can lead to a Denial of Service (DoS). NOTE: mu...
CVE-2022-33114HIGH7.2Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/syste...
CVE-2022-33113MEDIUM5.4Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyw...
CVE-2022-33105HIGH7.5Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.
CVE-2022-33097HIGH7.574cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_...
CVE-2022-33096HIGH7.574cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index.
CVE-2022-33095HIGH7.574cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resu...
CVE-2022-33094HIGH7.574cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map.
CVE-2022-33093HIGH7.574cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list.
CVE-2022-33092HIGH7.574cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index.
CVE-2022-33070MEDIUM5.5Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in proto...
CVE-2022-33069MEDIUM5.5Ethereum Solidity v0.8.14 contains an assertion failure via SMTEncoder::indexOrMemberAssignment() at SMTEncoder.cpp.
CVE-2022-33068MEDIUM5.5An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Se...
CVE-2022-33067MEDIUM5.5Lrzip v0.651 was discovered to contain multiple invalid arithmetic shifts via the functions get_magic in lrzip.c and Pre...
CVE-2022-33034HIGH7.8LibreDWG v0.12.4.4608 was discovered to contain a stack overflow via the function copy_bytes at decode_r2007.c.
CVE-2022-33033HIGH7.8LibreDWG v0.12.4.4608 was discovered to contain a double-free via the function dwg_read_file at dwg.c.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now