2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-33325 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.... |
| CVE-2022-33314 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.... |
| CVE-2022-33313 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.... |
| CVE-2022-33312 | CRITICAL | 9.8 | 4.4% | Jun 30, 2022 | Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.... |
| CVE-2022-32585 | CRITICAL | 9.8 | 2.5% | Jun 30, 2022 | A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0. A specially-crafted ne... |
| CVE-2022-2197 | CRITICAL | 9.8 | 1.3% | Jun 30, 2022 | By using a specific credential string, an attacker with network access to the device’s web interface could circumvent th... |
| CVE-2022-28127 | CRITICAL | 9.1 | 34.6% | Jun 30, 2022 | A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A speci... |
| CVE-2022-34818 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier does not perform permission checks in several views and HTTP end... |
| CVE-2022-34817 | MEDIUM | 4.3 | 0.4% | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier allows atta... |
| CVE-2022-34816 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenki... |
| CVE-2022-34815 | MEDIUM | 4.3 | 0.4% | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier allows at... |
| CVE-2022-34814 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier does not correctly perform a permission check in an HTTP endpo... |
| CVE-2022-34813 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/... |
| CVE-2022-34812 | MEDIUM | 4.3 | 0.4% | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows ... |
| CVE-2022-34811 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/... |
| CVE-2022-34810 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | A missing check in Jenkins RQM Plugin 2.8 and earlier allows attackers with Overall/Read permission to enumerate credent... |
| CVE-2022-34809 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins control... |
| CVE-2022-34808 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Je... |
| CVE-2022-34807 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the... |
| CVE-2022-34806 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller ... |
| CVE-2022-34805 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Je... |
| CVE-2022-34804 | MEDIUM | 4.3 | 0.4% | Jun 30, 2022 | Jenkins OpsGenie Plugin 1.9 and earlier transmits API keys in plain text as part of the global Jenkins configuration for... |
| CVE-2022-34803 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.x... |
| CVE-2022-34802 | MEDIUM | 4.3 | 0.6% | Jun 30, 2022 | Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its glob... |
| CVE-2022-34801 | MEDIUM | 4.3 | 0.4% | Jun 30, 2022 | Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins config... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now