2022 CVE Vulnerabilities
27,554 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-22272 | LOW | 3.3 | 0.1% | Jan 10, 2022 | Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRI... |
| CVE-2022-22271 | MEDIUM | 5.5 | 0.1% | Jan 10, 2022 | A missing input validation before memory copy in TIMA trustlet prior to SMR Jan-2022 Release 1 allows attackers to copy ... |
| CVE-2022-22270 | LOW | 3.3 | 0.2% | Jan 10, 2022 | An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to... |
| CVE-2022-22269 | LOW | 3.3 | 0.1% | Jan 10, 2022 | Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applica... |
| CVE-2022-22268 | MEDIUM | 6.1 | 0.1% | Jan 10, 2022 | Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporar... |
| CVE-2022-22267 | LOW | 3.3 | 0.1% | Jan 10, 2022 | Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get... |
| CVE-2022-22266 | LOW | 3.3 | 0.1% | Jan 10, 2022 | (Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-... |
| CVE-2022-22265 | HIGH | 7.8 | 0.4% | Jan 10, 2022 | An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary m... |
| CVE-2022-22264 | HIGH | 7.1 | 0.1% | Jan 10, 2022 | Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and... |
| CVE-2022-22263 | MEDIUM | 5.5 | 0.1% | Jan 10, 2022 | Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbi... |
| CVE-2022-21823 | MEDIUM | 5.5 | 0.3% | Jan 10, 2022 | A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that co... |
| CVE-2022-21667 | HIGH | 7.5 | 1.6% | Jan 10, 2022 | soketi is an open-source WebSockets server. There is an unhandled case when reading POST requests which results in the s... |
| CVE-2022-0133 | HIGH | 7.5 | 1.2% | Jan 10, 2022 | peertube is vulnerable to Improper Access Control |
| CVE-2022-0132 | HIGH | 7.5 | 0.9% | Jan 10, 2022 | peertube is vulnerable to Server-Side Request Forgery (SSRF) |
| CVE-2022-21664 | HIGH | 8.8 | 4.0% | Jan 6, 2022 | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to ... |
| CVE-2022-21663 | HIGH | 7.2 | 3.7% | Jan 6, 2022 | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a mu... |
| CVE-2022-21662 | MEDIUM | 5.4 | 64.7% | Jan 6, 2022 | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Low-pri... |
| CVE-2022-21661 | HIGH | 7.5 | 97.8% | Jan 6, 2022 | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to ... |
| CVE-2022-0128 | HIGH | 7.8 | 1.7% | Jan 6, 2022 | vim is vulnerable to Out-of-bounds Read |
| CVE-2022-22707 | MEDIUM | 5.9 | 9.0% | Jan 6, 2022 | In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based ... |
| CVE-2022-22704 | CRITICAL | 9.8 | 1.3% | Jan 6, 2022 | The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the des... |
| CVE-2022-0122 | MEDIUM | 6.1 | 0.8% | Jan 6, 2022 | forge is vulnerable to URL Redirection to Untrusted Site |
| CVE-2022-0121 | HIGH | 8 | 1.2% | Jan 6, 2022 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hoppscotch hoppsco... |
| CVE-2022-21653 | HIGH | 7.5 | 0.8% | Jan 5, 2022 | Jawn is an open source JSON parser. Extenders of the `org.typelevel.jawn.SimpleFacade` and `org.typelevel.jawn.MutableFa... |
| CVE-2022-21652 | HIGH | 8.1 | 0.8% | Jan 5, 2022 | Shopware is an open source e-commerce software platform. In affected versions shopware would not invalidate a user sessi... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now