2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-23114LOW3.3Jenkins Publish Over SSH Plugin 1.22 and earlier stores password unencrypted in its global configuration file on the Jen...
CVE-2022-23113MEDIUM4.3Jenkins Publish Over SSH Plugin 1.22 and earlier performs a validation of the file name specifying whether it is present...
CVE-2022-23112MEDIUM6.5A missing permission check in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers with Overall/Read access...
CVE-2022-23111MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over SSH Plugin 1.22 and earlier allows attackers t...
CVE-2022-23110MEDIUM4.8Jenkins Publish Over SSH Plugin 1.22 and earlier does not escape the SSH server name, resulting in a stored cross-site s...
CVE-2022-23109MEDIUM6.5Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline s...
CVE-2022-23108MEDIUM5.4Jenkins Badge Plugin 1.9 and earlier does not escape the description and does not check for allowed protocols when creat...
CVE-2022-23107HIGH8.1Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ...
CVE-2022-23106MEDIUM5.3Jenkins Configuration as Code Plugin 1.55 and earlier used a non-constant time comparison function when validating an au...
CVE-2022-23105MEDIUM6.5Jenkins Active Directory Plugin 2.25 and earlier does not encrypt the transmission of data between the Jenkins controlle...
CVE-2022-20621MEDIUM5.5Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenk...
CVE-2022-20620MEDIUM4.3Missing permission checks in Jenkins SSH Agent Plugin 1.23 and earlier allows attackers with Overall/Read access to enum...
CVE-2022-20619HIGH7.1A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlie...
CVE-2022-20618MEDIUM4.3A missing permission check in Jenkins Bitbucket Branch Source Plugin 737.vdf9dc06105be and earlier allows attackers with...
CVE-2022-20617HIGH8.8Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS comma...
CVE-2022-20616MEDIUM4.3Jenkins Credentials Binding Plugin 1.27 and earlier does not perform a permission check in a method implementing form va...
CVE-2022-20615MEDIUM5.4Jenkins Matrix Project Plugin 1.19 and earlier does not escape HTML metacharacters in node and label names, and label de...
CVE-2022-20614MEDIUM4.3A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read ...
CVE-2022-20613MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attac...
CVE-2022-20612MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins 2.329 and earlier, LTS 2.319.1 and earlier allows attackers...
CVE-2022-21676HIGH7.5Engine.IO is the implementation of transport-based cross-browser/cross-device bi-directional communication layer for Soc...
CVE-2022-21675HIGH7.8Bytecode Viewer (BCV) is a Java/Android reverse engineering suite. Versions of the package prior to 2.11.0 are vulnerabl...
CVE-2022-0015HIGH7.8A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables an authen...
CVE-2022-0014HIGH7.3An untrusted search path vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacker w...
CVE-2022-0013MEDIUM5.5A file information exposure vulnerability exists in the Palo Alto Networks Cortex XDR agent that enables a local attacke...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now