2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-25493MEDIUM6.1HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php.
CVE-2022-25489MEDIUM5.4Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /w...
CVE-2022-27218MEDIUM4.3Jenkins incapptic connect uploader Plugin 1.15 and earlier stores tokens unencrypted in job config.xml files on the Jenk...
CVE-2022-27217MEDIUM6.5Jenkins Vmware vRealize CodeStream Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Je...
CVE-2022-27216MEDIUM6.5Jenkins dbCharts Plugin 0.5.2 and earlier stores JDBC connection passwords unencrypted in its global configuration file ...
CVE-2022-27215MEDIUM4.3A missing permission check in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers with Overall/Read permiss...
CVE-2022-27214MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers to...
CVE-2022-27213MEDIUM5.4Jenkins Environment Dashboard Plugin 1.1.10 and earlier does not escape the Environment order and the Component order co...
CVE-2022-27212MEDIUM5.4Jenkins List Git Branches Parameter Plugin 0.0.9 and earlier does not escape the name of the 'List Git branches (and mor...
CVE-2022-27211MEDIUM6.5A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overal...
CVE-2022-27210MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allow...
CVE-2022-27209MEDIUM6.5A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overal...
CVE-2022-27208MEDIUM6.5Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read ar...
CVE-2022-27207MEDIUM4.8Jenkins global-build-stats Plugin 1.5 and earlier does not escape multiple fields in the chart configuration on the 'Glo...
CVE-2022-27206MEDIUM6.5Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.x...
CVE-2022-27205MEDIUM4.3A missing permission check in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers w...
CVE-2022-27203MEDIUM6.5Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Item/Configure permission ...
CVE-2022-27202MEDIUM5.4Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the value and description of ext...
CVE-2022-27201MEDIUM6.5Jenkins Semantic Versioning Plugin 1.13 and earlier does not restrict execution of an controller/agent message to agents...
CVE-2022-27200MEDIUM4.8Jenkins Folder-based Authorization Strategy Plugin 1.3 and earlier does not escape the names of roles shown on the confi...
CVE-2022-27199MEDIUM4.3A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers wi...
CVE-2022-27197MEDIUM5.4Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source UR...
CVE-2022-27196MEDIUM5.4Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a store...
CVE-2022-27195MEDIUM5.5Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Je...
CVE-2022-0970MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now