2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-27213 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Jenkins Environment Dashboard Plugin 1.1.10 and earlier does not escape the Environment order and the Component order co... |
| CVE-2022-27212 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Jenkins List Git Branches Parameter Plugin 0.0.9 and earlier does not escape the name of the 'List Git branches (and mor... |
| CVE-2022-27211 | MEDIUM | 6.5 | 0.9% | Mar 15, 2022 | A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overal... |
| CVE-2022-27210 | MEDIUM | 6.5 | 0.7% | Mar 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allow... |
| CVE-2022-27209 | MEDIUM | 6.5 | 0.9% | Mar 15, 2022 | A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overal... |
| CVE-2022-27208 | MEDIUM | 6.5 | 1.8% | Mar 15, 2022 | Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read ar... |
| CVE-2022-27207 | MEDIUM | 4.8 | 0.8% | Mar 15, 2022 | Jenkins global-build-stats Plugin 1.5 and earlier does not escape multiple fields in the chart configuration on the 'Glo... |
| CVE-2022-27206 | MEDIUM | 6.5 | 1.0% | Mar 15, 2022 | Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.x... |
| CVE-2022-27205 | MEDIUM | 4.3 | 0.7% | Mar 15, 2022 | A missing permission check in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers w... |
| CVE-2022-27204 | HIGH | 8.8 | 0.6% | Mar 15, 2022 | A cross-site request forgery vulnerability in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier al... |
| CVE-2022-27203 | MEDIUM | 6.5 | 1.5% | Mar 15, 2022 | Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Item/Configure permission ... |
| CVE-2022-27202 | MEDIUM | 5.4 | 0.6% | Mar 15, 2022 | Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the value and description of ext... |
| CVE-2022-27201 | MEDIUM | 6.5 | 1.3% | Mar 15, 2022 | Jenkins Semantic Versioning Plugin 1.13 and earlier does not restrict execution of an controller/agent message to agents... |
| CVE-2022-27200 | MEDIUM | 4.8 | 0.6% | Mar 15, 2022 | Jenkins Folder-based Authorization Strategy Plugin 1.3 and earlier does not escape the names of roles shown on the confi... |
| CVE-2022-27199 | MEDIUM | 4.3 | 0.7% | Mar 15, 2022 | A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers wi... |
| CVE-2022-27198 | HIGH | 8 | 0.5% | Mar 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earl... |
| CVE-2022-27197 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source UR... |
| CVE-2022-27196 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a store... |
| CVE-2022-27195 | MEDIUM | 5.5 | 0.4% | Mar 15, 2022 | Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Je... |
| CVE-2022-22771 | HIGH | 8.8 | 2.1% | Mar 15, 2022 | The Server component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix ... |
| CVE-2022-0970 | MEDIUM | 5.4 | 1.8% | Mar 15, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31. |
| CVE-2022-0778 | HIGH | 7.5 | 70.6% | Mar 15, 2022 | The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for n... |
| CVE-2022-26779 | HIGH | 7.5 | 2.8% | Mar 15, 2022 | Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project i... |
| CVE-2022-0968 | MEDIUM | 5.5 | 3.7% | Mar 15, 2022 | The microweber application allows large characters to insert in the input field "fist & last name" which can allow attac... |
| CVE-2022-0967 | MEDIUM | 5.4 | 3.3% | Mar 15, 2022 | Stored XSS via File Upload in star7th/showdoc in star7th/showdoc in GitHub repository star7th/showdoc prior to 2.10.4. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now