2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-0436 | MEDIUM | 5.5 | 0.6% | Apr 12, 2022 | Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2. |
| CVE-2022-29052 | MEDIUM | 4.3 | 0.7% | Apr 12, 2022 | Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent config.xml files o... |
| CVE-2022-29051 | MEDIUM | 4.3 | 0.7% | Apr 12, 2022 | Missing permission checks in Jenkins Publish Over FTP Plugin 1.16 and earlier allow attackers with Overall/Read permissi... |
| CVE-2022-29050 | HIGH | 8.8 | 0.7% | Apr 12, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over FTP Plugin 1.16 and earlier allows attackers t... |
| CVE-2022-29049 | MEDIUM | 5.4 | 0.8% | Apr 12, 2022 | Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the names of promotions ... |
| CVE-2022-29048 | MEDIUM | 4.3 | 1.7% | Apr 12, 2022 | A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Plugin 2.15.3 and earlier allows attackers to co... |
| CVE-2022-29047 | MEDIUM | 5.3 | 1.1% | Apr 12, 2022 | Jenkins Pipeline: Shared Groovy Libraries Plugin 564.ve62a_4eb_b_e039 and earlier, except 2.21.3, allows attackers able ... |
| CVE-2022-29046 | MEDIUM | 5.4 | 2.3% | Apr 12, 2022 | Jenkins Subversion Plugin 2.15.3 and earlier does not escape the name and description of List Subversion tags (and more)... |
| CVE-2022-29045 | MEDIUM | 5.4 | 0.8% | Apr 12, 2022 | Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not escape the name and description o... |
| CVE-2022-29044 | MEDIUM | 5.4 | 0.6% | Apr 12, 2022 | Jenkins Node and Label parameter Plugin 1.10.3 and earlier does not escape the name and description of Node and Label pa... |
| CVE-2022-29043 | MEDIUM | 5.4 | 0.8% | Apr 12, 2022 | Jenkins Mask Passwords Plugin 3.0 and earlier does not escape the name and description of Non-Stored Password parameters... |
| CVE-2022-29042 | MEDIUM | 5.4 | 0.8% | Apr 12, 2022 | Jenkins Job Generator Plugin 1.22 and earlier does not escape the name and description of Generator Parameter and Genera... |
| CVE-2022-29041 | MEDIUM | 5.4 | 0.8% | Apr 12, 2022 | Jenkins Jira Plugin 3.7 and earlier, except 3.6.1, does not escape the name and description of Jira Issue and Jira Relea... |
| CVE-2022-29040 | MEDIUM | 5.4 | 0.8% | Apr 12, 2022 | Jenkins Git Parameter Plugin 0.9.15 and earlier does not escape the name and description of Git parameters on views disp... |
| CVE-2022-29039 | MEDIUM | 5.4 | 0.8% | Apr 12, 2022 | Jenkins Gerrit Trigger Plugin 2.35.2 and earlier does not escape the name and description of Base64 Encoded String param... |
| CVE-2022-29038 | MEDIUM | 5.4 | 0.6% | Apr 12, 2022 | Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier does not escape the name and description of Exte... |
| CVE-2022-29037 | MEDIUM | 5.4 | 0.6% | Apr 12, 2022 | Jenkins CVS Plugin 2.19 and earlier does not escape the name and description of CVS Symbolic Name parameters on views di... |
| CVE-2022-29036 | MEDIUM | 5.4 | 81.5% | Apr 12, 2022 | Jenkins Credentials Plugin 1111.v35a_307992395 and earlier, except 1087.1089.v2f1b_9a_b_040e4, 1074.1076.v39c30cecb_0e2,... |
| CVE-2022-27419 | MEDIUM | 5.5 | 0.6% | Apr 12, 2022 | rtl_433 21.12 was discovered to contain a stack overflow in the function acurite_00275rm_decode at /devices/acurite.c. T... |
| CVE-2022-27418 | HIGH | 7.8 | 0.8% | Apr 12, 2022 | Tcpreplay v4.4.1 has a heap-based buffer overflow in do_checksum_math at /tcpedit/checksum.c. |
| CVE-2022-27416 | HIGH | 7.8 | 0.8% | Apr 12, 2022 | Tcpreplay v4.4.1 was discovered to contain a double-free via __interceptor_free. |
| CVE-2022-27387 | HIGH | 7.5 | 2.3% | Apr 12, 2022 | MariaDB Server v10.7 and below was discovered to contain a global buffer overflow in the component decimal_bin_size, whi... |
| CVE-2022-27386 | HIGH | 7.5 | 2.2% | Apr 12, 2022 | MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc. |
| CVE-2022-27385 | HIGH | 7.5 | 1.6% | Apr 12, 2022 | An issue in the component Used_tables_and_const_cache::used_tables_and_const_cache_join of MariaDB Server v10.7 and belo... |
| CVE-2022-27384 | HIGH | 7.5 | 2.1% | Apr 12, 2022 | An issue in the component Item_subselect::init_expr_cache_tracker of MariaDB Server v10.6 and below was discovered to al... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now