2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-23114 | LOW | 3.3 | 0.3% | Jan 12, 2022 | Jenkins Publish Over SSH Plugin 1.22 and earlier stores password unencrypted in its global configuration file on the Jen... |
| CVE-2022-23113 | MEDIUM | 4.3 | 1.5% | Jan 12, 2022 | Jenkins Publish Over SSH Plugin 1.22 and earlier performs a validation of the file name specifying whether it is present... |
| CVE-2022-23112 | MEDIUM | 6.5 | 0.9% | Jan 12, 2022 | A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access... |
| CVE-2022-23111 | MEDIUM | 4.3 | 27.6% | Jan 12, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers t... |
| CVE-2022-23110 | MEDIUM | 4.8 | 0.8% | Jan 12, 2022 | Jenkins Publish Over SSH Plugin 1.22 and earlier does not escape the SSH server name, resulting in a stored cross-site s... |
| CVE-2022-23109 | MEDIUM | 6.5 | 1.0% | Jan 12, 2022 | Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline s... |
| CVE-2022-23108 | MEDIUM | 5.4 | 0.8% | Jan 12, 2022 | Jenkins Badge Plugin 1.9 and earlier does not escape the description and does not check for allowed protocols when creat... |
| CVE-2022-23107 | HIGH | 8.1 | 1.9% | Jan 12, 2022 | Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ... |
| CVE-2022-23106 | MEDIUM | 5.3 | 1.1% | Jan 12, 2022 | Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an au... |
| CVE-2022-23105 | MEDIUM | 6.5 | 0.4% | Jan 12, 2022 | Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controlle... |
| CVE-2022-20621 | MEDIUM | 5.5 | 0.3% | Jan 12, 2022 | Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenk... |
| CVE-2022-20620 | MEDIUM | 4.3 | 0.7% | Jan 12, 2022 | Missing permission checks in Jenkins SSH Agent Plugin 1.23 and earlier allows attackers with Overall/Read access to enum... |
| CVE-2022-20619 | HIGH | 7.1 | 0.7% | Jan 12, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlie... |
| CVE-2022-20618 | MEDIUM | 4.3 | 0.9% | Jan 12, 2022 | A missing permission check in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers with... |
| CVE-2022-20617 | HIGH | 8.8 | 2.3% | Jan 12, 2022 | Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS comma... |
| CVE-2022-20616 | MEDIUM | 4.3 | 0.9% | Jan 12, 2022 | Jenkins Credentials Binding Plugin 1.27 and earlier does not perform a permission check in a method implementing form va... |
| CVE-2022-20615 | MEDIUM | 5.4 | 81.8% | Jan 12, 2022 | Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label de... |
| CVE-2022-20614 | MEDIUM | 4.3 | 1.1% | Jan 12, 2022 | A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read ... |
| CVE-2022-20613 | MEDIUM | 4.3 | 1.0% | Jan 12, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attac... |
| CVE-2022-20612 | MEDIUM | 4.3 | 1.8% | Jan 12, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers... |
| CVE-2022-21676 | HIGH | 7.5 | 2.8% | Jan 12, 2022 | Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Soc... |
| CVE-2022-21675 | HIGH | 7.8 | 2.5% | Jan 12, 2022 | Bytecode Viewer (BCV) is a Java/Android reverse engineering suite. Versions of the package prior to 2.11.0 are vulnerabl... |
| CVE-2022-0015 | HIGH | 7.8 | 0.2% | Jan 12, 2022 | A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authen... |
| CVE-2022-0014 | HIGH | 7.3 | 0.3% | Jan 12, 2022 | An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker w... |
| CVE-2022-0013 | MEDIUM | 5.5 | 0.2% | Jan 12, 2022 | A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacke... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now