2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-25193MEDIUM6.5Missing permission checks in Jenkins Snow Commander Plugin 1.10 and earlier allow attackers with Overall/Read permission...
CVE-2022-25191MEDIUM5.4Jenkins Agent Server Parameter Plugin 1.0 and earlier does not escape parameter names of agent server parameters, result...
CVE-2022-25190MEDIUM4.3A missing permission check in Jenkins Conjur Secrets Plugin 1.0.11 and earlier allows attackers with Overall/Read permis...
CVE-2022-25189MEDIUM5.4Jenkins Custom Checkbox Parameter Plugin 1.1 and earlier does not escape parameter names of custom checkbox parameters, ...
CVE-2022-25188MEDIUM4.3Jenkins Fortify Plugin 20.2.34 and earlier does not sanitize the appName and appVersion parameters of its Pipeline steps...
CVE-2022-25187MEDIUM6.5Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.
CVE-2022-25186MEDIUM6.5Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Va...
CVE-2022-25185MEDIUM5.4Jenkins Generic Webhook Trigger Plugin 1.81 and earlier does not escape the build cause when using the webhook, resultin...
CVE-2022-25184MEDIUM6.5Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipelin...
CVE-2022-25180MEDIUM4.3Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in r...
CVE-2022-25179MEDIUM6.5Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the ch...
CVE-2022-25178MEDIUM6.5Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier does not restrict the names of resources ...
CVE-2022-25177MEDIUM6.5Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier follows symbolic links to locations outsi...
CVE-2022-25176MEDIUM6.5Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checko...
CVE-2022-24590MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to ex...
CVE-2022-24588MEDIUM5.4Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function.
CVE-2022-24587MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attacke...
CVE-2022-24585MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attac...
CVE-2022-24684MEDIUM6.5HashiCorp Nomad and Nomad Enterprise 0.9.0 through 1.0.16, 1.1.11, and 1.2.5 allow operators with job-submit capabilitie...
CVE-2022-24227MEDIUM6.1A cross-site scripting (XSS) vulnerability in BoltWire v7.10 and v 8.00 allows attackers to execute arbitrary web script...
CVE-2022-24586MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows at...
CVE-2022-0597MEDIUM6.1Open Redirect in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0596MEDIUM4.3Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11.
CVE-2022-0589MEDIUM5.4Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0.
CVE-2022-0588MEDIUM6.5Missing Authorization in Packagist librenms/librenms prior to 22.2.0.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now