2022 CVE Vulnerabilities
27,538 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-41248 | MEDIUM | 5.3 | 0.3% | Sep 21, 2022 | Jenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, ... |
| CVE-2022-41247 | MEDIUM | 4.3 | 0.4% | Sep 21, 2022 | Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration f... |
| CVE-2022-41246 | MEDIUM | 6.5 | 0.6% | Sep 21, 2022 | A missing permission check in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier allows attackers with Ove... |
| CVE-2022-41245 | HIGH | 8.8 | 0.4% | Sep 21, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Worksoft Execution Manager Plugin 10.0.3.503 and earlier al... |
| CVE-2022-41244 | HIGH | 8.1 | 0.5% | Sep 21, 2022 | Jenkins View26 Test-Reporting Plugin 1.0.7 and earlier does not perform hostname validation when connecting to the confi... |
| CVE-2022-41243 | HIGH | 8.1 | 0.5% | Sep 21, 2022 | Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26... |
| CVE-2022-41242 | MEDIUM | 5.4 | 0.4% | Sep 21, 2022 | A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permiss... |
| CVE-2022-41241 | CRITICAL | 9.1 | 0.7% | Sep 21, 2022 | Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2022-41240 | MEDIUM | 5.4 | 0.5% | Sep 21, 2022 | Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored ... |
| CVE-2022-41239 | MEDIUM | 5.4 | 0.6% | Sep 21, 2022 | Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications... |
| CVE-2022-41238 | CRITICAL | 9.8 | 0.9% | Sep 21, 2022 | A missing permission check in Jenkins DotCi Plugin 2.40.00 and earlier allows unauthenticated attackers to trigger build... |
| CVE-2022-41237 | CRITICAL | 9.8 | 1.3% | Sep 21, 2022 | Jenkins DotCi Plugin 2.40.00 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary ty... |
| CVE-2022-41236 | HIGH | 8.8 | 0.4% | Sep 21, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Security Inspector Plugin 117.v6eecc36919c2 and earlier all... |
| CVE-2022-41235 | MEDIUM | 5.3 | 0.6% | Sep 21, 2022 | Jenkins WildFly Deployer Plugin 1.0.2 and earlier implements functionality that allows agent processes to read arbitrary... |
| CVE-2022-41234 | HIGH | 8.8 | 0.8% | Sep 21, 2022 | Jenkins Rundeck Plugin 3.6.11 and earlier does not protect access to the /plugin/rundeck/webhook/ endpoint, allowing use... |
| CVE-2022-41233 | MEDIUM | 4.3 | 0.5% | Sep 21, 2022 | Jenkins Rundeck Plugin 3.6.11 and earlier does not perform Run/Artifacts permission checks in multiple HTTP endpoints, a... |
| CVE-2022-41232 | HIGH | 8 | 0.4% | Sep 21, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers to... |
| CVE-2022-41231 | MEDIUM | 5.7 | 1.2% | Sep 21, 2022 | Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any... |
| CVE-2022-41230 | MEDIUM | 4.3 | 0.5% | Sep 21, 2022 | Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attack... |
| CVE-2022-41229 | MEDIUM | 5.4 | 0.5% | Sep 21, 2022 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of th... |
| CVE-2022-41228 | HIGH | 8.8 | 0.8% | Sep 21, 2022 | A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attack... |
| CVE-2022-41227 | HIGH | 8.8 | 0.4% | Sep 21, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 an... |
| CVE-2022-41226 | CRITICAL | 9.8 | 0.8% | Sep 21, 2022 | Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML extern... |
| CVE-2022-41225 | MEDIUM | 5.4 | 0.6% | Sep 21, 2022 | Jenkins Anchore Container Image Scanner Plugin 1.0.24 and earlier does not escape content provided by the Anchore engine... |
| CVE-2022-41224 | MEDIUM | 5.4 | 0.9% | Sep 21, 2022 | Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now