2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25980 | CRITICAL | 9.8 | 1.2% | Mar 29, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in H... |
| CVE-2022-25880 | CRITICAL | 9.8 | 1.2% | Mar 29, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability exists in Handle... |
| CVE-2022-25347 | HIGH | 7.5 | 11.1% | Mar 29, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow... |
| CVE-2022-22941 | HIGH | 8.8 | 1.3% | Mar 29, 2022 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. When configured as a Master-of-Mast... |
| CVE-2022-22936 | HIGH | 8.8 | 0.8% | Mar 29, 2022 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Job publishes and file server repli... |
| CVE-2022-22935 | LOW | 3.7 | 1.6% | Mar 29, 2022 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. A minion authentication denial of s... |
| CVE-2022-22934 | HIGH | 8.8 | 0.9% | Mar 29, 2022 | An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1. Salt Masters do not sign pillar dat... |
| CVE-2022-1050 | HIGH | 8.8 | 0.4% | Mar 29, 2022 | A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. This flaw allows a crafted guest driver... |
| CVE-2022-0923 | CRITICAL | 9.8 | 1.0% | Mar 29, 2022 | Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) has a blind SQL injection vulnerability that exists in H... |
| CVE-2022-0343 | HIGH | 7.8 | 0.1% | Mar 29, 2022 | A local attacker, as a different local user, may be able to send a HTTP request to 127.0.0.1:10000 after the user (typic... |
| CVE-2022-1055 | HIGH | 7.8 | 0.5% | Mar 29, 2022 | A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escala... |
| CVE-2022-28160 | MEDIUM | 6.5 | 1.1% | Mar 29, 2022 | Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on t... |
| CVE-2022-28159 | MEDIUM | 5.4 | 0.8% | Mar 29, 2022 | Jenkins Tests Selector Plugin 1.3.3 and earlier does not escape the Properties File Path option for Choosing Tests param... |
| CVE-2022-28158 | MEDIUM | 6.5 | 0.7% | Mar 29, 2022 | A missing permission check in Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Overall/Re... |
| CVE-2022-28157 | MEDIUM | 6.5 | 1.4% | Mar 29, 2022 | Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to upload arbi... |
| CVE-2022-28156 | MEDIUM | 6.5 | 1.5% | Mar 29, 2022 | Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier allows attackers with Item/Configure permission to copy arbitr... |
| CVE-2022-28155 | HIGH | 8.1 | 0.8% | Mar 29, 2022 | Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external enti... |
| CVE-2022-28154 | HIGH | 8.1 | 1.0% | Mar 29, 2022 | Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML exter... |
| CVE-2022-28153 | MEDIUM | 5.4 | 0.8% | Mar 29, 2022 | Jenkins SiteMonitor Plugin 0.6 and earlier does not escape URLs of sites to monitor in tooltips, resulting in a stored c... |
| CVE-2022-28152 | MEDIUM | 4.3 | 0.6% | Mar 29, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows att... |
| CVE-2022-28151 | MEDIUM | 4.3 | 0.7% | Mar 29, 2022 | A missing permission check in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows attackers with Item/Read p... |
| CVE-2022-28150 | HIGH | 8.8 | 0.7% | Mar 29, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Job and Node ownership Plugin 0.13.0 and earlier allows att... |
| CVE-2022-28149 | MEDIUM | 5.4 | 0.8% | Mar 29, 2022 | Jenkins Job and Node ownership Plugin 0.13.0 and earlier does not escape the names of the secondary owners, resulting in... |
| CVE-2022-28148 | MEDIUM | 6.5 | 1.8% | Mar 29, 2022 | The file browser in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier may interpret some paths to fil... |
| CVE-2022-28147 | MEDIUM | 4.3 | 0.7% | Mar 29, 2022 | A missing permission check in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now