2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-36902 | MEDIUM | 5.4 | 0.6% | Jul 27, 2022 | Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape several fields of Moded Extended Choi... |
| CVE-2022-36901 | MEDIUM | 6.5 | 0.7% | Jul 27, 2022 | Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file ... |
| CVE-2022-36898 | MEDIUM | 4.3 | 0.6% | Jul 27, 2022 | A missing permission check in Jenkins Compuware ISPW Operations Plugin 1.0.8 and earlier allows attackers with Overall/R... |
| CVE-2022-36897 | MEDIUM | 4.3 | 0.5% | Jul 27, 2022 | A missing permission check in Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier allows attackers with Ov... |
| CVE-2022-36896 | MEDIUM | 6.5 | 0.6% | Jul 27, 2022 | A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlie... |
| CVE-2022-36895 | MEDIUM | 4.3 | 0.5% | Jul 27, 2022 | A missing permission check in Jenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier allows attackers with Overall/R... |
| CVE-2022-36894 | MEDIUM | 6.5 | 0.7% | Jul 27, 2022 | An arbitrary file write vulnerability in Jenkins CLIF Performance Testing Plugin 64.vc0d66de1dfb_f and earlier allows at... |
| CVE-2022-36893 | MEDIUM | 4.3 | 0.6% | Jul 27, 2022 | Jenkins rpmsign-plugin Plugin 0.5.0 and earlier does not perform a permission check in a method implementing form valida... |
| CVE-2022-36892 | MEDIUM | 4.3 | 0.5% | Jul 27, 2022 | Jenkins rhnpush-plugin Plugin 0.5.1 and earlier does not perform a permission check in a method implementing form valida... |
| CVE-2022-36891 | MEDIUM | 4.3 | 0.5% | Jul 27, 2022 | A missing permission check in Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier allows attackers with Item/... |
| CVE-2022-36890 | MEDIUM | 4.3 | 1.0% | Jul 27, 2022 | Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the name of files in methods implementi... |
| CVE-2022-36888 | MEDIUM | 6.5 | 0.6% | Jul 27, 2022 | A missing permission check in Jenkins HashiCorp Vault Plugin 354.vdb_858fd6b_f48 and earlier allows attackers with Overa... |
| CVE-2022-36887 | MEDIUM | 4.3 | 0.4% | Jul 27, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Job Configuration History Plugin 1155.v28a_46a_cc06a_5 and ... |
| CVE-2022-36886 | MEDIUM | 4.3 | 0.4% | Jul 27, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins External Monitor Job Type Plugin 191.v363d0d1efdf8 and earl... |
| CVE-2022-36885 | MEDIUM | 5.3 | 0.7% | Jul 27, 2022 | Jenkins GitHub Plugin 1.34.4 and earlier uses a non-constant time comparison function when checking whether the provided... |
| CVE-2022-36884 | MEDIUM | 5.3 | 0.8% | Jul 27, 2022 | The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the ex... |
| CVE-2022-2549 | MEDIUM | 5.5 | 0.5% | Jul 27, 2022 | NULL Pointer Dereference in GitHub repository gpac/gpac prior to v2.1.0-DEV. |
| CVE-2022-34551 | MEDIUM | 6.5 | 0.8% | Jul 27, 2022 | Sims v1.0 was discovered to allow path traversal when downloading attachments. |
| CVE-2022-34550 | MEDIUM | 5.4 | 0.4% | Jul 27, 2022 | Sims v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /addNotifyServlet. This... |
| CVE-2022-34529 | MEDIUM | 5.5 | 0.3% | Jul 27, 2022 | WASM3 v0.5.0 was discovered to contain a segmentation fault via the component Compile_Memory_CopyFill. |
| CVE-2022-24406 | MEDIUM | 6.5 | 0.8% | Jul 27, 2022 | OX App Suite through 7.10.6 allows SSRF because multipart/form-data boundaries are predictable, and this can lead to inj... |
| CVE-2022-23101 | MEDIUM | 6.1 | 0.6% | Jul 27, 2022 | OX App Suite through 7.10.6 allows XSS via appHandler in a deep link in an e-mail message. |
| CVE-2022-23099 | MEDIUM | 5.4 | 0.6% | Jul 27, 2022 | OX App Suite through 7.10.6 allows XSS by forcing block-wise read. |
| CVE-2022-36880 | MEDIUM | 6.1 | 0.5% | Jul 27, 2022 | The Read Mail module in Webmin 1.995 and Usermin through 1.850 allows XSS via a crafted HTML e-mail message. |
| CVE-2022-36879 | MEDIUM | 5.5 | 0.3% | Jul 27, 2022 | An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now