2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34800 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the ... |
| CVE-2022-34799 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on... |
| CVE-2022-34798 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, al... |
| CVE-2022-34797 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attac... |
| CVE-2022-34796 | MEDIUM | 4.3 | 0.6% | Jun 30, 2022 | A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers with Overall/Read ... |
| CVE-2022-34795 | MEDIUM | 5.4 | 0.6% | Jun 30, 2022 | Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard vie... |
| CVE-2022-34794 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send ... |
| CVE-2022-34793 | HIGH | 8.8 | 0.8% | Jun 30, 2022 | Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2022-34792 | HIGH | 8 | 0.4% | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an H... |
| CVE-2022-34791 | MEDIUM | 5.4 | 0.6% | Jun 30, 2022 | Jenkins Validating Email Parameter Plugin 1.10 and earlier does not escape the name and description of its parameter typ... |
| CVE-2022-34790 | MEDIUM | 5.4 | 0.6% | Jun 30, 2022 | Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a s... |
| CVE-2022-34789 | MEDIUM | 6.5 | 0.5% | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers t... |
| CVE-2022-34788 | MEDIUM | 5.4 | 0.5% | Jun 30, 2022 | Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross... |
| CVE-2022-34787 | MEDIUM | 5.4 | 0.5% | Jun 30, 2022 | Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resul... |
| CVE-2022-34786 | MEDIUM | 5.4 | 0.5% | Jun 30, 2022 | Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resultin... |
| CVE-2022-34785 | MEDIUM | 4.3 | 0.6% | Jun 30, 2022 | Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing att... |
| CVE-2022-34784 | MEDIUM | 5.4 | 0.7% | Jun 30, 2022 | Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-... |
| CVE-2022-34783 | MEDIUM | 5.4 | 80.4% | Jun 30, 2022 | Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XS... |
| CVE-2022-34782 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read pe... |
| CVE-2022-34781 | MEDIUM | 6.5 | 0.6% | Jun 30, 2022 | Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read pe... |
| CVE-2022-34780 | MEDIUM | 6.5 | 0.4% | Jun 30, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attac... |
| CVE-2022-34779 | MEDIUM | 4.3 | 0.5% | Jun 30, 2022 | A missing permission check in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers with Overall/Read ... |
| CVE-2022-34778 | MEDIUM | 5.4 | 0.5% | Jun 30, 2022 | Jenkins TestNG Results Plugin 554.va4a552116332 and earlier renders the unescaped test descriptions and exception messag... |
| CVE-2022-34777 | MEDIUM | 5.4 | 72.4% | Jun 30, 2022 | Jenkins GitLab Plugin 1.5.34 and earlier does not escape multiple fields inserted into the description of webhook-trigge... |
| CVE-2022-31112 | HIGH | 8.2 | 1.0% | Jun 30, 2022 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected vers... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now