2022 CVE Vulnerabilities

27,518 CVEs published in 2022.

Filter:LOWClear
CVE IDSeverityCVSSDescription
CVE-2022-29053LOW3.3A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version ...
CVE-2022-1697LOW3.9Okta Active Directory Agent versions 3.8.0 through 3.11.0 installed the Okta AD Agent Update Service using an unquoted p...
CVE-2022-2256LOW3.8A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This fla...
CVE-2022-2556LOW2.7The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perfo...
CVE-2022-36168LOW2.7A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:
CVE-2022-36117LOW3.1An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment that exposes the Blue ...
CVE-2022-31237LOW3.3Dell PowerScale OneFS, versions 9.2.0 up to and including 9.2.1.12 and 9.3.0.5 contain an improper preservation of permi...
CVE-2022-34771LOW3.5Tabit - arbitrary SMS send on Tabits behalf. The resend OTP API of tabit allows an adversary to send messages on tabits ...
CVE-2022-2841LOW2.7A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problemati...
CVE-2022-37438LOW3.5In Splunk Enterprise versions in the following table, an authenticated user can craft a dashboard that could potentially...
CVE-2022-36007LOW3.3Venice is a Clojure inspired sandboxed Lisp dialect with excellent Java interoperability. A partial path traversal issue...
CVE-2022-20342LOW3.3In WiFi, there is a possible disclosure of WiFi password to the end user due to an insecure default value. This could le...
CVE-2022-20340LOW3.3In SELinux policy, there is a possible way of inferring which websites are being opened in the browser due to a missing ...
CVE-2022-20339LOW3.3In Android, there is a possible access of network neighbor table information due to an insecure SEpolicy configuration. ...
CVE-2022-20338LOW3.3In HierarchicalUri.readFrom of Uri.java, there is a possible way to craft a malformed Uri object due to improper input v...
CVE-2022-20336LOW3.3In Settings, there is a possible installed application disclosure due to a missing permission check. This could lead to ...
CVE-2022-20335LOW3.3In Wifi Slice, there is a possible way to adjust Wi-Fi settings even when the permission has been disabled due to a miss...
CVE-2022-20330LOW3.5In Bluetooth, there is a possible way to connect or disconnect bluetooth devices without user awareness due to a missing...
CVE-2022-20328LOW3.3In PackageManager, there is a possible way to determine whether an app is installed due to a missing permission check. T...
CVE-2022-20327LOW2.8In Wi-Fi, there is a possible way to retrieve the WiFi SSID without location permissions due to a missing permission che...
CVE-2022-20321LOW3.3In Settings, there is a possible way for an application without permissions to read content of WiFi QR codes due to a mi...
CVE-2022-20320LOW3.3In ActivityManager, there is a possible way to determine whether an app is installed, without query permissions, due to ...
CVE-2022-20318LOW3.3In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to...
CVE-2022-20316LOW3.3In ContentResolver, there is a possible way to determine whether an app is installed, without query permissions, due to ...
CVE-2022-20315LOW3.3In ActivityManager, there is a possible disclosure of installed packages due to a missing permission check. This could l...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now