2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20480 | HIGH | 7.8 | 0.2% | Dec 13, 2022 | In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to r... |
| CVE-2022-20479 | HIGH | 7.8 | 0.2% | Dec 13, 2022 | In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to r... |
| CVE-2022-20478 | HIGH | 7.8 | 0.2% | Dec 13, 2022 | In NotificationChannel of NotificationChannel.java, there is a possible failure to persist permissions settings due to r... |
| CVE-2022-20477 | HIGH | 7.8 | 0.1% | Dec 13, 2022 | In shouldHideNotification of KeyguardNotificationVisibilityProvider.kt, there is a possible way to show hidden notificat... |
| CVE-2022-20475 | HIGH | 7.8 | 0.1% | Dec 13, 2022 | In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" d... |
| CVE-2022-20474 | HIGH | 7.8 | 0.2% | Dec 13, 2022 | In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a con... |
| CVE-2022-20470 | HIGH | 7.8 | 0.2% | Dec 13, 2022 | In bindRemoteViewsService of AppWidgetServiceImpl.java, there is a possible way to bypass background activity launch due... |
| CVE-2022-20469 | HIGH | 8.8 | 0.2% | Dec 13, 2022 | In avct_lcb_msg_asmbl of avct_lcb_act.cc, there is a possible out of bounds write due to a missing bounds check. This co... |
| CVE-2022-20442 | HIGH | 7.3 | 0.1% | Dec 13, 2022 | In onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API ... |
| CVE-2022-20411 | HIGH | 8.8 | 1.9% | Dec 13, 2022 | In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead... |
| CVE-2022-46363 | HIGH | 7.5 | 1.2% | Dec 13, 2022 | A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing ... |
| CVE-2022-45871 | HIGH | 7.5 | 0.4% | Dec 13, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the ... |
| CVE-2022-45693 | HIGH | 7.5 | 1.4% | Dec 13, 2022 | Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attac... |
| CVE-2022-45690 | HIGH | 7.5 | 0.9% | Dec 13, 2022 | A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attacke... |
| CVE-2022-45689 | HIGH | 7.5 | 0.8% | Dec 13, 2022 | hutool-json v5.8.10 was discovered to contain an out of memory error. |
| CVE-2022-45688 | HIGH | 7.5 | 1.2% | Dec 13, 2022 | A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service ... |
| CVE-2022-45685 | HIGH | 7.5 | 1.4% | Dec 13, 2022 | A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data. |
| CVE-2022-29580 | HIGH | 7.8 | 0.4% | Dec 13, 2022 | There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of u... |
| CVE-2022-4098 | HIGH | 8 | 0.3% | Dec 13, 2022 | Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. Aft... |
| CVE-2022-23505 | HIGH | 7.5 | 0.8% | Dec 13, 2022 | Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prio... |
| CVE-2022-41272 | HIGH | 8.6 | 1.0% | Dec 13, 2022 | An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Se... |
| CVE-2022-41268 | HIGH | 7.5 | 0.6% | Dec 13, 2022 | In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, ... |
| CVE-2022-41267 | HIGH | 8.8 | 0.8% | Dec 13, 2022 | SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/repla... |
| CVE-2022-41264 | HIGH | 8.8 | 0.9% | Dec 13, 2022 | Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 7... |
| CVE-2022-45269 | HIGH | 7.5 | 3.1% | Dec 12, 2022 | A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attacke... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now