2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34812 | MEDIUM | 4.3 | 0.4% | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows ... |
| CVE-2022-34811 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/... |
| CVE-2022-34810 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | A missing check in Jenkins RQM Plugin 2.8 and earlier allows attackers with Overall/Read permission to enumerate credent... |
| CVE-2022-34809 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins control... |
| CVE-2022-34808 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Je... |
| CVE-2022-34807 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the... |
| CVE-2022-34806 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller ... |
| CVE-2022-34805 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Je... |
| CVE-2022-34804 | MEDIUM | 4.3 | 0.4% | Jun 30, 2022 | Jenkins OpsGenie Plugin 1.9 and earlier transmits API keys in plain text as part of the global Jenkins configuration for... |
| CVE-2022-34803 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.x... |
| CVE-2022-34802 | MEDIUM | 4.3 | 0.6% | Jun 30, 2022 | Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its glob... |
| CVE-2022-34801 | MEDIUM | 4.3 | 0.4% | Jun 30, 2022 | Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins config... |
| CVE-2022-34800 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the ... |
| CVE-2022-34799 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on... |
| CVE-2022-34798 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, al... |
| CVE-2022-34797 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attac... |
| CVE-2022-34796 | MEDIUM | 4.3 | 0.6% | Jun 30, 2022 | A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers with Overall/Read ... |
| CVE-2022-34795 | MEDIUM | 5.4 | 0.6% | Jun 30, 2022 | Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard vie... |
| CVE-2022-34794 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send ... |
| CVE-2022-34791 | MEDIUM | 5.4 | 0.6% | Jun 30, 2022 | Jenkins Validating Email Parameter Plugin 1.10 and earlier does not escape the name and description of its parameter typ... |
| CVE-2022-34790 | MEDIUM | 5.4 | 0.6% | Jun 30, 2022 | Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a s... |
| CVE-2022-34789 | MEDIUM | 6.5 | 0.5% | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers t... |
| CVE-2022-34788 | MEDIUM | 5.4 | 0.5% | Jun 30, 2022 | Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross... |
| CVE-2022-34787 | MEDIUM | 5.4 | 0.5% | Jun 30, 2022 | Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resul... |
| CVE-2022-34786 | MEDIUM | 5.4 | 0.5% | Jun 30, 2022 | Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resultin... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now