2022 CVE Vulnerabilities

27,531 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-43418MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Katalon Plugin 1.0.33 and earlier allows attackers to conne...
CVE-2022-43417MEDIUM4.3Jenkins Katalon Plugin 1.0.32 and earlier does not perform permission checks in several HTTP endpoints, allowing attacke...
CVE-2022-43416HIGH8.8Jenkins Katalon Plugin 1.0.32 and earlier implements an agent/controller message that does not limit where it can be exe...
CVE-2022-43415HIGH7.5Jenkins REPO Plugin 1.15.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-43414MEDIUM5.3Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specifie...
CVE-2022-43413MEDIUM4.3Jenkins Job Import Plugin 3.5 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers wi...
CVE-2022-43412MEDIUM5.3Jenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whe...
CVE-2022-43411MEDIUM5.3Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided...
CVE-2022-43410MEDIUM5.3Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or schedu...
CVE-2022-43409MEDIUM5.4Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of h...
CVE-2022-43408MEDIUM6.5Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to ...
CVE-2022-43407HIGH8.8Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specifi...
CVE-2022-43406CRITICAL9.9A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier al...
CVE-2022-43405CRITICAL9.9A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier allows attack...
CVE-2022-43404CRITICAL9.9A sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated synthetic constructor...
CVE-2022-43403CRITICAL9.9A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin ...
CVE-2022-43402CRITICAL9.9A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pi...
CVE-2022-43401CRITICAL9.9A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Sc...
CVE-2022-43185MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows atta...
CVE-2022-43184CRITICAL9.8D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc....
CVE-2022-43045MEDIUM5.5GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_dump_vrml_s...
CVE-2022-43044MEDIUM5.5GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_get_me...
CVE-2022-43043MEDIUM5.5GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function BD_CheckSFTime...
CVE-2022-43042HIGH7.8GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function FixSDTPInTRAF at...
CVE-2022-43040HIGH7.8GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function gf_isom_box_dump...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now