2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28146MEDIUM6.5Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Item/Configure permission to ...
CVE-2022-28145MEDIUM5.4Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier does not apply Content-Security-Policy headers to r...
CVE-2022-28144MEDIUM6.5Jenkins Proxmox Plugin 0.7.0 and earlier does not perform a permission check in several HTTP endpoints, allowing attacke...
CVE-2022-28143MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Proxmox Plugin 0.7.0 and earlier allows attackers to connec...
CVE-2022-28142HIGH7.5Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM...
CVE-2022-28141MEDIUM6.5Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the global config.xml fil...
CVE-2022-28140HIGH8.1Jenkins Flaky Test Handler Plugin 1.2.1 and earlier does not configure its XML parser to prevent XML external entity (XX...
CVE-2022-28139MEDIUM4.3A missing permission check in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attackers with Overall/Read p...
CVE-2022-28138MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins RocketChat Notifier Plugin 1.4.10 and earlier allows attack...
CVE-2022-28137MEDIUM4.3A missing permission check in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier allows attackers with ...
CVE-2022-28136HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins JiraTestResultReporter Plugin 165.v817928553942 and earlier...
CVE-2022-28135MEDIUM6.5Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configurati...
CVE-2022-28134MEDIUM5.4Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not perform permission checks in several HTTP endpoin...
CVE-2022-28133MEDIUM5.4Jenkins Bitbucket Server Integration Plugin 3.1.0 and earlier does not limit URL schemes for callback URLs on OAuth cons...
CVE-2022-23903MEDIUM5.4A Cross Site Scripting (XSS) vulnerability exists in pearadmin pear-admin-think <=5.0.6, which allows a login account to...
CVE-2022-23901CRITICAL9.8A stack overflow re2c 2.2 exists due to infinite recursion issues in src/dfa/dead_rules.cc.
CVE-2022-23059MEDIUM4.8A Stored Cross Site Scripting (XSS) vulnerability exists in Shopizer versions 2.0 through 2.17.0 via the “Manage Images”...
CVE-2022-1032HIGH7.2Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.
CVE-2022-1087MEDIUM5.4A vulnerability, which was classified as problematic, has been found in htmly 5.3 whis affects the component Edit Profil...
CVE-2022-1086MEDIUM5.4A vulnerability was found in DolphinPHP up to 1.5.0 and classified as problematic. Affected by this issue is the User Ma...
CVE-2022-1085MEDIUM6.1A vulnerability was found in CLTPHP up to 6.0. It has been declared as problematic. Affected by this vulnerability is th...
CVE-2022-1084CRITICAL9.8A vulnerability classified as critical was found in SourceCodester One Church Management System 1.0. Affected by this vu...
CVE-2022-1083CRITICAL9.8A vulnerability classified as critical has been found in Microfinance Management System. The manipulation of arguments l...
CVE-2022-1082CRITICAL9.8A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been rated as critical. This issu...
CVE-2022-1081MEDIUM6.1A vulnerability was found in SourceCodester Microfinance Management System 1.0. It has been declared as problematic. Thi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now