2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25193 | MEDIUM | 6.5 | 0.9% | Feb 15, 2022 | Missing permission checks in Jenkins Snow Commander Plugin 1.10 and earlier allow attackers with Overall/Read permission... |
| CVE-2022-25191 | MEDIUM | 5.4 | 0.6% | Feb 15, 2022 | Jenkins Agent Server Parameter Plugin 1.0 and earlier does not escape parameter names of agent server parameters, result... |
| CVE-2022-25190 | MEDIUM | 4.3 | 0.7% | Feb 15, 2022 | A missing permission check in Jenkins Conjur Secrets Plugin 1.0.11 and earlier allows attackers with Overall/Read permis... |
| CVE-2022-25189 | MEDIUM | 5.4 | 0.6% | Feb 15, 2022 | Jenkins Custom Checkbox Parameter Plugin 1.1 and earlier does not escape parameter names of custom checkbox parameters, ... |
| CVE-2022-25188 | MEDIUM | 4.3 | 1.2% | Feb 15, 2022 | Jenkins Fortify Plugin 20.2.34 and earlier does not sanitize the appName and appVersion parameters of its Pipeline steps... |
| CVE-2022-25187 | MEDIUM | 6.5 | 1.0% | Feb 15, 2022 | Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle. |
| CVE-2022-25186 | MEDIUM | 6.5 | 0.8% | Feb 15, 2022 | Jenkins HashiCorp Vault Plugin 3.8.0 and earlier implements functionality that allows agent processes to retrieve any Va... |
| CVE-2022-25185 | MEDIUM | 5.4 | 0.6% | Feb 15, 2022 | Jenkins Generic Webhook Trigger Plugin 1.81 and earlier does not escape the build cause when using the webhook, resultin... |
| CVE-2022-25184 | MEDIUM | 6.5 | 0.9% | Feb 15, 2022 | Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipelin... |
| CVE-2022-25180 | MEDIUM | 4.3 | 0.5% | Feb 15, 2022 | Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier includes password parameters from the original build in r... |
| CVE-2022-25179 | MEDIUM | 6.5 | 1.8% | Feb 15, 2022 | Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier follows symbolic links to locations outside of the ch... |
| CVE-2022-25178 | MEDIUM | 6.5 | 1.6% | Feb 15, 2022 | Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier does not restrict the names of resources ... |
| CVE-2022-25177 | MEDIUM | 6.5 | 1.7% | Feb 15, 2022 | Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier follows symbolic links to locations outsi... |
| CVE-2022-25176 | MEDIUM | 6.5 | 1.7% | Feb 15, 2022 | Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier follows symbolic links to locations outside of the checko... |
| CVE-2022-24590 | MEDIUM | 5.4 | 0.6% | Feb 15, 2022 | A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to ex... |
| CVE-2022-24588 | MEDIUM | 5.4 | 0.7% | Feb 15, 2022 | Flatpress v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability in the Upload SVG File function. |
| CVE-2022-24587 | MEDIUM | 5.4 | 0.7% | Feb 15, 2022 | A stored cross-site scripting (XSS) vulnerability in the component core/admin/medias.php of PluXml v5.8.7 allows attacke... |
| CVE-2022-24585 | MEDIUM | 5.4 | 0.7% | Feb 15, 2022 | A stored cross-site scripting (XSS) vulnerability in the component /core/admin/comment.php of PluXml v5.8.7 allows attac... |
| CVE-2022-24684 | MEDIUM | 6.5 | 1.4% | Feb 15, 2022 | HashiCorp Nomad and Nomad Enterprise 0.9.0 through 1.0.16, 1.1.11, and 1.2.5 allow operators with job-submit capabilitie... |
| CVE-2022-24227 | MEDIUM | 6.1 | 2.2% | Feb 15, 2022 | A cross-site scripting (XSS) vulnerability in BoltWire v7.10 and v 8.00 allows attackers to execute arbitrary web script... |
| CVE-2022-24586 | MEDIUM | 5.4 | 0.7% | Feb 15, 2022 | A stored cross-site scripting (XSS) vulnerability in the component /core/admin/categories.php of PluXml v5.8.7 allows at... |
| CVE-2022-0597 | MEDIUM | 6.1 | 3.0% | Feb 15, 2022 | Open Redirect in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-0596 | MEDIUM | 4.3 | 0.6% | Feb 15, 2022 | Improper Validation of Specified Quantity in Input in Packagist microweber/microweber prior to 1.2.11. |
| CVE-2022-0589 | MEDIUM | 5.4 | 0.8% | Feb 15, 2022 | Cross-site Scripting (XSS) - Stored in Packagist librenms/librenms prior to 22.1.0. |
| CVE-2022-0588 | MEDIUM | 6.5 | 1.1% | Feb 15, 2022 | Missing Authorization in Packagist librenms/librenms prior to 22.2.0. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now