2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34800MEDIUM4.3Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the ...
CVE-2022-34799MEDIUM4.3Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on...
CVE-2022-34798MEDIUM4.3Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, al...
CVE-2022-34797MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attac...
CVE-2022-34796MEDIUM4.3A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers with Overall/Read ...
CVE-2022-34795MEDIUM5.4Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard vie...
CVE-2022-34794MEDIUM6.5Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send ...
CVE-2022-34793HIGH8.8Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-34792HIGH8A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an H...
CVE-2022-34791MEDIUM5.4Jenkins Validating Email Parameter Plugin 1.10 and earlier does not escape the name and description of its parameter typ...
CVE-2022-34790MEDIUM5.4Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a s...
CVE-2022-34789MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers t...
CVE-2022-34788MEDIUM5.4Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross...
CVE-2022-34787MEDIUM5.4Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resul...
CVE-2022-34786MEDIUM5.4Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resultin...
CVE-2022-34785MEDIUM4.3Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing att...
CVE-2022-34784MEDIUM5.4Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-...
CVE-2022-34783MEDIUM5.4Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XS...
CVE-2022-34782MEDIUM4.3An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read pe...
CVE-2022-34781MEDIUM6.5Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read pe...
CVE-2022-34780MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attac...
CVE-2022-34779MEDIUM4.3A missing permission check in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers with Overall/Read ...
CVE-2022-34778MEDIUM5.4Jenkins TestNG Results Plugin 554.va4a552116332 and earlier renders the unescaped test descriptions and exception messag...
CVE-2022-34777MEDIUM5.4Jenkins GitLab Plugin 1.5.34 and earlier does not escape multiple fields inserted into the description of webhook-trigge...
CVE-2022-31112HIGH8.2Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In affected vers...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now