2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-30968MEDIUM5.4Jenkins vboxwrapper Plugin 1.3 and earlier does not escape the name and description of VBox node parameters on views dis...
CVE-2022-30967MEDIUM5.4Jenkins Selection tasks Plugin 1.0 and earlier does not escape the name and description of Script Selection task variabl...
CVE-2022-30966MEDIUM5.4Jenkins Random String Parameter Plugin 1.0 and earlier does not escape the name and description of Random String paramet...
CVE-2022-30965MEDIUM5.4Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level para...
CVE-2022-30964MEDIUM5.4Jenkins Multiselect parameter Plugin 1.3 and earlier does not escape the name and description of Multiselect parameters ...
CVE-2022-30963MEDIUM5.4Jenkins JDK Parameter Plugin 1.0 and earlier does not escape the name and description of JDK parameters on views display...
CVE-2022-30962MEDIUM5.4Jenkins Global Variable String Parameter Plugin 1.2 and earlier does not escape the name and description of Global Varia...
CVE-2022-30961MEDIUM5.4Jenkins Autocomplete Parameter Plugin 1.1 and earlier does not escape the name of Dropdown Autocomplete and Auto Complet...
CVE-2022-30960MEDIUM5.4Jenkins Application Detector Plugin 1.0.8 and earlier does not escape the name of Chois Application Version parameters o...
CVE-2022-30959MEDIUM6.5A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to conn...
CVE-2022-30958HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins SSH Plugin 2.6.1 and earlier allows attackers to connect to...
CVE-2022-30957MEDIUM4.3A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to enum...
CVE-2022-30956MEDIUM5.4Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a s...
CVE-2022-30955MEDIUM6.5Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers wit...
CVE-2022-30954MEDIUM6.5Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing att...
CVE-2022-30953MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Blue Ocean Plugin 1.25.3 and earlier allows attackers to co...
CVE-2022-30952MEDIUM6.5Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to acce...
CVE-2022-30951HIGH8.8Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access ...
CVE-2022-30950HIGH8.8Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library which has a buffer overflo...
CVE-2022-30949MEDIUM5.3Jenkins REPO Plugin 1.14.0 and earlier allows attackers able to configure pipelines to check out some SCM repositories s...
CVE-2022-30948HIGH7.5Jenkins Mercurial Plugin 2.16 and earlier allows attackers able to configure pipelines to check out some SCM repositorie...
CVE-2022-30947HIGH7.5Jenkins Git Plugin 4.11.1 and earlier allows attackers able to configure pipelines to check out some SCM repositories st...
CVE-2022-30946MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Script Security Plugin 1158.v7c1b_73a_69a_08 and earlier al...
CVE-2022-30945HIGH8.5Jenkins Pipeline: Groovy Plugin 2689.v434009a_31b_f1 and earlier allows loading any Groovy source files on the classpath...
CVE-2022-30110MEDIUM6.1The file preview functionality in Jirafeau < 4.4.0, which is enabled by default, could be exploited for cross site scrip...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now