2022 CVE Vulnerabilities
27,531 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-43418 | MEDIUM | 4.3 | 0.4% | Oct 19, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Katalon Plugin 1.0.33 and earlier allows attackers to conne... |
| CVE-2022-43417 | MEDIUM | 4.3 | 0.6% | Oct 19, 2022 | Jenkins Katalon Plugin 1.0.32 and earlier does not perform permission checks in several HTTP endpoints, allowing attacke... |
| CVE-2022-43416 | HIGH | 8.8 | 1.1% | Oct 19, 2022 | Jenkins Katalon Plugin 1.0.32 and earlier implements an agent/controller message that does not limit where it can be exe... |
| CVE-2022-43415 | HIGH | 7.5 | 0.9% | Oct 19, 2022 | Jenkins REPO Plugin 1.15.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2022-43414 | MEDIUM | 5.3 | 0.6% | Oct 19, 2022 | Jenkins NUnit Plugin 0.27 and earlier implements an agent-to-controller message that parses files inside a user-specifie... |
| CVE-2022-43413 | MEDIUM | 4.3 | 0.5% | Oct 19, 2022 | Jenkins Job Import Plugin 3.5 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers wi... |
| CVE-2022-43412 | MEDIUM | 5.3 | 0.5% | Oct 19, 2022 | Jenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whe... |
| CVE-2022-43411 | MEDIUM | 5.3 | 0.7% | Oct 19, 2022 | Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided... |
| CVE-2022-43410 | MEDIUM | 5.3 | 0.7% | Oct 19, 2022 | Jenkins Mercurial Plugin 1251.va_b_121f184902 and earlier provides information about which jobs were triggered or schedu... |
| CVE-2022-43409 | MEDIUM | 5.4 | 0.7% | Oct 19, 2022 | Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of h... |
| CVE-2022-43408 | MEDIUM | 6.5 | 0.4% | Oct 19, 2022 | Jenkins Pipeline: Stage View Plugin 2.26 and earlier does not correctly encode the ID of 'input' steps when using it to ... |
| CVE-2022-43407 | HIGH | 8.8 | 0.5% | Oct 19, 2022 | Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specifi... |
| CVE-2022-43406 | CRITICAL | 9.9 | 1.1% | Oct 19, 2022 | A sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin 583.vf3b_454e43966 and earlier al... |
| CVE-2022-43405 | CRITICAL | 9.9 | 1.2% | Oct 19, 2022 | A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin 612.v84da_9c54906d and earlier allows attack... |
| CVE-2022-43404 | CRITICAL | 9.9 | 1.1% | Oct 19, 2022 | A sandbox bypass vulnerability involving crafted constructor bodies and calls to sandbox-generated synthetic constructor... |
| CVE-2022-43403 | CRITICAL | 9.9 | 1.4% | Oct 19, 2022 | A sandbox bypass vulnerability involving casting an array-like value to an array type in Jenkins Script Security Plugin ... |
| CVE-2022-43402 | CRITICAL | 9.9 | 1.2% | Oct 19, 2022 | A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Pi... |
| CVE-2022-43401 | CRITICAL | 9.9 | 1.2% | Oct 19, 2022 | A sandbox bypass vulnerability involving various casts performed implicitly by the Groovy language runtime in Jenkins Sc... |
| CVE-2022-43185 | MEDIUM | 5.4 | 1.0% | Oct 19, 2022 | A stored cross-site scripting (XSS) vulnerability in the Configuration/Holidays module of Rukovoditel v3.2.1 allows atta... |
| CVE-2022-43184 | CRITICAL | 9.8 | 1.7% | Oct 19, 2022 | D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.... |
| CVE-2022-43045 | MEDIUM | 5.5 | 0.3% | Oct 19, 2022 | GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_dump_vrml_s... |
| CVE-2022-43044 | MEDIUM | 5.5 | 0.3% | Oct 19, 2022 | GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function gf_isom_get_me... |
| CVE-2022-43043 | MEDIUM | 5.5 | 0.3% | Oct 19, 2022 | GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a segmentation violation via the function BD_CheckSFTime... |
| CVE-2022-43042 | HIGH | 7.8 | 0.3% | Oct 19, 2022 | GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function FixSDTPInTRAF at... |
| CVE-2022-43040 | HIGH | 7.8 | 0.3% | Oct 19, 2022 | GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function gf_isom_box_dump... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now