2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34298 | MEDIUM | 5.3 | 3.1% | Jun 23, 2022 | The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack." |
| CVE-2022-34295 | MEDIUM | 6.5 | 1.5% | Jun 23, 2022 | totd before 1.5.3 does not properly randomize mesg IDs. |
| CVE-2022-34213 | MEDIUM | 6.5 | 0.7% | Jun 23, 2022 | Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configu... |
| CVE-2022-34212 | MEDIUM | 5.7 | 0.6% | Jun 23, 2022 | A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read pe... |
| CVE-2022-34211 | MEDIUM | 6.5 | 0.5% | Jun 23, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attacke... |
| CVE-2022-34210 | MEDIUM | 6.5 | 0.6% | Jun 23, 2022 | A missing permission check in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers with Overall/Read permission t... |
| CVE-2022-34209 | MEDIUM | 6.5 | 0.6% | Jun 23, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins ThreadFix Plugin 1.5.4 and earlier allows attackers to conn... |
| CVE-2022-34208 | MEDIUM | 4.3 | 0.6% | Jun 23, 2022 | A missing permission check in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers with Overall/Read permissi... |
| CVE-2022-34207 | MEDIUM | 6.5 | 0.5% | Jun 23, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Beaker builder Plugin 1.10 and earlier allows attackers to ... |
| CVE-2022-34206 | MEDIUM | 4.3 | 0.5% | Jun 23, 2022 | A missing permission check in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attackers with Overall/Read pe... |
| CVE-2022-34205 | MEDIUM | 6.5 | 0.5% | Jun 23, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Jianliao Notification Plugin 1.1 and earlier allows attacke... |
| CVE-2022-34204 | MEDIUM | 4.3 | 0.5% | Jun 23, 2022 | A missing permission check in Jenkins EasyQA Plugin 1.0 and earlier allows attackers with Overall/Read permission to con... |
| CVE-2022-34202 | MEDIUM | 6.5 | 0.6% | Jun 23, 2022 | Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins ... |
| CVE-2022-34201 | MEDIUM | 6.5 | 0.6% | Jun 23, 2022 | A missing permission check in Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier allows attackers with Overall/Re... |
| CVE-2022-34199 | MEDIUM | 6.5 | 0.6% | Jun 23, 2022 | Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Je... |
| CVE-2022-34198 | MEDIUM | 5.4 | 0.7% | Jun 23, 2022 | Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier does not escape the name and description of Stash Branch paramet... |
| CVE-2022-34197 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins Sauce OnDemand Plugin 1.204 and earlier does not escape the name and description of Sauce Labs Browsers paramete... |
| CVE-2022-34196 | MEDIUM | 5.4 | 0.8% | Jun 23, 2022 | Jenkins REST List Parameter Plugin 1.5.2 and earlier does not escape the name and description of REST list parameters on... |
| CVE-2022-34195 | MEDIUM | 5.4 | 0.8% | Jun 23, 2022 | Jenkins Repository Connector Plugin 2.2.0 and earlier does not escape the name and description of Maven Repository Artif... |
| CVE-2022-34194 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins Readonly Parameter Plugin 1.0.0 and earlier does not escape the name and description of Readonly String and Read... |
| CVE-2022-34193 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins Package Version Plugin 1.0.1 and earlier does not escape the name of Package version parameters on views display... |
| CVE-2022-34192 | MEDIUM | 5.4 | 0.8% | Jun 23, 2022 | Jenkins ontrack Jenkins Plugin 4.0.0 and earlier does not escape the name of Ontrack: Multi Parameter choice, Ontrack: P... |
| CVE-2022-34191 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.77 and earlier does not escape the name of NetStorm Test pa... |
| CVE-2022-34190 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.1 and earlier does not escape the name and description of L... |
| CVE-2022-34189 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now