2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25493 | MEDIUM | 6.1 | 0.8% | Mar 15, 2022 | HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php. |
| CVE-2022-25489 | MEDIUM | 5.4 | 1.5% | Mar 15, 2022 | Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /w... |
| CVE-2022-27218 | MEDIUM | 4.3 | 0.7% | Mar 15, 2022 | Jenkins incapptic connect uploader Plugin 1.15 and earlier stores tokens unencrypted in job config.xml files on the Jenk... |
| CVE-2022-27217 | MEDIUM | 6.5 | 0.9% | Mar 15, 2022 | Jenkins Vmware vRealize CodeStream Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Je... |
| CVE-2022-27216 | MEDIUM | 6.5 | 0.9% | Mar 15, 2022 | Jenkins dbCharts Plugin 0.5.2 and earlier stores JDBC connection passwords unencrypted in its global configuration file ... |
| CVE-2022-27215 | MEDIUM | 4.3 | 0.7% | Mar 15, 2022 | A missing permission check in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers with Overall/Read permiss... |
| CVE-2022-27214 | MEDIUM | 4.3 | 0.5% | Mar 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers to... |
| CVE-2022-27213 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Jenkins Environment Dashboard Plugin 1.1.10 and earlier does not escape the Environment order and the Component order co... |
| CVE-2022-27212 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Jenkins List Git Branches Parameter Plugin 0.0.9 and earlier does not escape the name of the 'List Git branches (and mor... |
| CVE-2022-27211 | MEDIUM | 6.5 | 0.9% | Mar 15, 2022 | A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overal... |
| CVE-2022-27210 | MEDIUM | 6.5 | 0.7% | Mar 15, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allow... |
| CVE-2022-27209 | MEDIUM | 6.5 | 0.9% | Mar 15, 2022 | A missing permission check in Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows attackers with Overal... |
| CVE-2022-27208 | MEDIUM | 6.5 | 1.8% | Mar 15, 2022 | Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read ar... |
| CVE-2022-27207 | MEDIUM | 4.8 | 0.8% | Mar 15, 2022 | Jenkins global-build-stats Plugin 1.5 and earlier does not escape multiple fields in the chart configuration on the 'Glo... |
| CVE-2022-27206 | MEDIUM | 6.5 | 1.0% | Mar 15, 2022 | Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.x... |
| CVE-2022-27205 | MEDIUM | 4.3 | 0.7% | Mar 15, 2022 | A missing permission check in Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers w... |
| CVE-2022-27203 | MEDIUM | 6.5 | 1.5% | Mar 15, 2022 | Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Item/Configure permission ... |
| CVE-2022-27202 | MEDIUM | 5.4 | 0.6% | Mar 15, 2022 | Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the value and description of ext... |
| CVE-2022-27201 | MEDIUM | 6.5 | 1.3% | Mar 15, 2022 | Jenkins Semantic Versioning Plugin 1.13 and earlier does not restrict execution of an controller/agent message to agents... |
| CVE-2022-27200 | MEDIUM | 4.8 | 0.6% | Mar 15, 2022 | Jenkins Folder-based Authorization Strategy Plugin 1.3 and earlier does not escape the names of roles shown on the confi... |
| CVE-2022-27199 | MEDIUM | 4.3 | 0.7% | Mar 15, 2022 | A missing permission check in Jenkins CloudBees AWS Credentials Plugin 189.v3551d5642995 and earlier allows attackers wi... |
| CVE-2022-27197 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Jenkins Dashboard View Plugin 2.18 and earlier does not perform URL validation for the Iframe Portlet's Iframe source UR... |
| CVE-2022-27196 | MEDIUM | 5.4 | 0.8% | Mar 15, 2022 | Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a store... |
| CVE-2022-27195 | MEDIUM | 5.5 | 0.4% | Mar 15, 2022 | Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Je... |
| CVE-2022-0970 | MEDIUM | 5.4 | 1.8% | Mar 15, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository getgrav/grav prior to 1.7.31. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now