CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2022-28127

    Last Modified: 15 Apr 2025

    A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary file deletion. An attacker can send a sequence of requests to trigger this vulnerability.

    Published: 30 Jun 2022
    —
    Unknown

    CVE-2013-4252

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none

    Published: 30 Jun 2022
    9.8
    Critical

    CVE-2022-2197

    Last Modified: 16 Apr 2025

    By using a specific credential string, an attacker with network access to the device’s web interface could circumvent the authentication scheme and perform administrative operations.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34818

    Last Modified: 21 Nov 2024

    Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier does not perform permission checks in several views and HTTP endpoints, allowing attackers with Overall/Read permission to disable jobs.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34817

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier allows attackers to disable jobs.

    Published: 30 Jun 2022
    6.5
    Medium

    CVE-2022-34816

    Last Modified: 21 Nov 2024

    Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34815

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier allows attackers to accept pending requests, thereby renaming or deleting jobs.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34814

    Last Modified: 21 Nov 2024

    Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view an administrative configuration page listing pending requests.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34813

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to create and delete XPath expressions.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34812

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers to create and delete XPath expressions.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34811

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to access the XPath Configuration Viewer page.

    Published: 30 Jun 2022
    6.5
    Medium

    CVE-2022-34810

    Last Modified: 21 Nov 2024

    A missing check in Jenkins RQM Plugin 2.8 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

    Published: 30 Jun 2022
    6.5
    Medium

    CVE-2022-34809

    Last Modified: 21 Nov 2024

    Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34808

    Last Modified: 21 Nov 2024

    Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

    Published: 30 Jun 2022
    6.5
    Medium

    CVE-2022-34807

    Last Modified: 21 Nov 2024

    Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

    Published: 30 Jun 2022
    6.5
    Medium

    CVE-2022-34806

    Last Modified: 21 Nov 2024

    Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

    Published: 30 Jun 2022
    6.5
    Medium

    CVE-2022-34805

    Last Modified: 21 Nov 2024

    Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34804

    Last Modified: 21 Nov 2024

    Jenkins OpsGenie Plugin 1.9 and earlier transmits API keys in plain text as part of the global Jenkins configuration form and job configuration forms, potentially resulting in their exposure.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34803

    Last Modified: 21 Nov 2024

    Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission (config.xml), or access to the Jenkins controller file system.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34802

    Last Modified: 21 Nov 2024

    Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34801

    Last Modified: 21 Nov 2024

    Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34800

    Last Modified: 21 Nov 2024

    Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34799

    Last Modified: 21 Nov 2024

    Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34798

    Last Modified: 21 Nov 2024

    Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34797

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers to connect to an attacker-specified HTTP URL using attacker-specified credentials.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34796

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

    Published: 30 Jun 2022
    5.4
    Medium

    CVE-2022-34795

    Last Modified: 21 Nov 2024

    Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard view, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.

    Published: 30 Jun 2022
    6.5
    Medium

    CVE-2022-34794

    Last Modified: 21 Nov 2024

    Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML.

    Published: 30 Jun 2022
    8.8
    High

    CVE-2022-34793

    Last Modified: 21 Nov 2024

    Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 30 Jun 2022
    8
    High

    CVE-2022-34792

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Recipe Plugin 1.2 and earlier allows attackers to send an HTTP request to an attacker-specified URL and parse the response as XML.

    Published: 30 Jun 2022
    5.4
    Medium

    CVE-2022-34791

    Last Modified: 21 Nov 2024

    Jenkins Validating Email Parameter Plugin 1.10 and earlier does not escape the name and description of its parameter type, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 30 Jun 2022
    5.4
    Medium

    CVE-2022-34790

    Last Modified: 21 Nov 2024

    Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 30 Jun 2022
    6.5
    Medium

    CVE-2022-34789

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers to rebuild previous matrix builds.

    Published: 30 Jun 2022
    5.4
    Medium

    CVE-2022-34788

    Last Modified: 21 Nov 2024

    Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.

    Published: 30 Jun 2022
    5.4
    Medium

    CVE-2022-34787

    Last Modified: 21 Nov 2024

    Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control the reason a queue item is blocked.

    Published: 30 Jun 2022
    5.4
    Medium

    CVE-2022-34786

    Last Modified: 21 Nov 2024

    Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34785

    Last Modified: 21 Nov 2024

    Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about jobs otherwise inaccessible to them.

    Published: 30 Jun 2022
    5.4
    Medium

    CVE-2022-34784

    Last Modified: 21 Nov 2024

    Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Build/Update permission.

    Published: 30 Jun 2022
    5.4
    Medium

    CVE-2022-34783

    Last Modified: 21 Nov 2024

    Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34782

    Last Modified: 21 Nov 2024

    An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read permission to view the list of pending requests.

    Published: 30 Jun 2022
    6.5
    Medium

    CVE-2022-34781

    Last Modified: 21 Nov 2024

    Missing permission checks in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 30 Jun 2022
    6.5
    Medium

    CVE-2022-34780

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2022-34779

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins XebiaLabs XL Release Plugin 22.0.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

    Published: 30 Jun 2022
    5.4
    Medium

    CVE-2022-34778

    Last Modified: 21 Nov 2024

    Jenkins TestNG Results Plugin 554.va4a552116332 and earlier renders the unescaped test descriptions and exception messages provided in test results if certain job-level options are set, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or control test results.

    Published: 30 Jun 2022
    5.4
    Medium

    CVE-2022-34777

    Last Modified: 21 Nov 2024

    Jenkins GitLab Plugin 1.5.34 and earlier does not escape multiple fields inserted into the description of webhook-triggered builds, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

    Published: 30 Jun 2022
    9.8
    Critical

    CVE-2013-4144

    Last Modified: 21 Nov 2024

    There is an object injection vulnerability in swfupload plugin for wordpress.

    Published: 30 Jun 2022
    5.3
    Medium

    CVE-2022-22494

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.

    Published: 30 Jun 2022
    8.8
    High

    CVE-2022-22472

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control restrictions, caused by improper disclosure of session information. By retrieving the logs of a container an attacker could exploit this vulnerability to bypass login security of the IBM Spectrum Protect Plus server and gain unauthorized access based on the permissions of the IBM Spectrum Protect Plus user to the vulnerable Spectrum Protect Plus server software. IBM X-Force ID: 225340.

    Published: 30 Jun 2022
    4.3
    Medium

    CVE-2021-38954

    Last Modified: 21 Nov 2024

    IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could disclose sensitive version information that could aid in future attacks against the system. IBM X-Force ID: 211414.

    Published: 30 Jun 2022
    8.1
    High

    CVE-2021-38941

    Last Modified: 21 Nov 2024

    IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable to host information leakage or destruction if unauthorized access to these containers could execute arbitrary commands. IBM X-Force ID: 211048.

    Published: 30 Jun 2022