2022 CVE Vulnerabilities

27,554 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-22272LOW3.3Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRI...
CVE-2022-22271MEDIUM5.5A missing input validation before memory copy in TIMA trustlet prior to SMR Jan-2022 Release 1 allows attackers to copy ...
CVE-2022-22270LOW3.3An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to...
CVE-2022-22269LOW3.3Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applica...
CVE-2022-22268MEDIUM6.1Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporar...
CVE-2022-22267LOW3.3Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get...
CVE-2022-22266LOW3.3(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-...
CVE-2022-22265HIGH7.8An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary m...
CVE-2022-22264HIGH7.1Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and...
CVE-2022-22263MEDIUM5.5Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbi...
CVE-2022-21823MEDIUM5.5A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that co...
CVE-2022-21667HIGH7.5soketi is an open-source WebSockets server. There is an unhandled case when reading POST requests which results in the s...
CVE-2022-0133HIGH7.5peertube is vulnerable to Improper Access Control
CVE-2022-0132HIGH7.5peertube is vulnerable to Server-Side Request Forgery (SSRF)
CVE-2022-21664HIGH8.8WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to ...
CVE-2022-21663HIGH7.2WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a mu...
CVE-2022-21662MEDIUM5.4WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-pri...
CVE-2022-21661HIGH7.5WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to ...
CVE-2022-0128HIGH7.8vim is vulnerable to Out-of-bounds Read
CVE-2022-22707MEDIUM5.9In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based ...
CVE-2022-22704CRITICAL9.8The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the des...
CVE-2022-0122MEDIUM6.1forge is vulnerable to URL Redirection to Untrusted Site
CVE-2022-0121HIGH8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppsco...
CVE-2022-21653HIGH7.5Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFa...
CVE-2022-21652HIGH8.1Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user sessi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now