2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-48454 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial ... |
| CVE-2022-3007 | HIGH | 8.1 | 0.3% | Oct 31, 2023 | The vulnerability exists in Syska SW100 Smartwatch due to an improper implementation and/or configuration of Nordic Devi... |
| CVE-2022-39172 | MEDIUM | 5.4 | 0.6% | Oct 30, 2023 | A stored XSS in the process overview (bersicht zugewiesener Vorgaenge) in mbsupport openVIVA c2 20220101 allows a remote... |
| CVE-2022-20264 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due ... |
| CVE-2022-4575 | MEDIUM | 6.7 | 0.2% | Oct 30, 2023 | A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models cou... |
| CVE-2022-4574 | MEDIUM | 6.7 | 0.2% | Oct 30, 2023 | An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local ac... |
| CVE-2022-4573 | MEDIUM | 6.7 | 0.2% | Oct 30, 2023 | An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access a... |
| CVE-2022-48189 | MEDIUM | 6.7 | 0.2% | Oct 30, 2023 | An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local acce... |
| CVE-2022-48190 | — | — | — | Oct 30, 2023 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2022-34834 | MEDIUM | 4.8 | 0.4% | Oct 27, 2023 | An issue was discovered in VERMEG AgileReporter 21.3. Attackers can gain privileges via an XSS payload in an Add Comment... |
| CVE-2022-34833 | MEDIUM | 5.4 | 0.4% | Oct 27, 2023 | An issue was discovered in VERMEG AgileReporter 21.3. An admin can enter an XSS payload in the Analysis component. |
| CVE-2022-34832 | MEDIUM | 6.5 | 0.7% | Oct 27, 2023 | An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component. |
| CVE-2022-3702 | HIGH | 7.1 | 0.1% | Oct 27, 2023 | A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that c... |
| CVE-2022-3701 | HIGH | 7.8 | 0.1% | Oct 27, 2023 | A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlie... |
| CVE-2022-3700 | MEDIUM | 6.3 | 0.1% | Oct 27, 2023 | A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.... |
| CVE-2022-3681 | MEDIUM | 6.5 | 0.2% | Oct 27, 2023 | A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range o... |
| CVE-2022-3611 | HIGH | 7.5 | 0.4% | Oct 27, 2023 | An information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to... |
| CVE-2022-3429 | MEDIUM | 6.5 | 0.5% | Oct 27, 2023 | A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malform... |
| CVE-2022-34887 | MEDIUM | 5.4 | 0.3% | Oct 27, 2023 | Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers with... |
| CVE-2022-34886 | HIGH | 8.8 | 0.9% | Oct 27, 2023 | A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a r... |
| CVE-2022-4886 | MEDIUM | 6.5 | 1.6% | Oct 25, 2023 | Ingress-nginx `path` sanitization can be bypassed with `log_format` directive. |
| CVE-2022-3699 | HIGH | 7.8 | 4.3% | Oct 25, 2023 | A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo ... |
| CVE-2022-3698 | MEDIUM | 4.4 | 0.2% | Oct 25, 2023 | A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Len... |
| CVE-2022-38485 | MEDIUM | 6.5 | 3.1% | Oct 25, 2023 | A directory traversal vulnerability exists in the AgeVolt Portal prior to version 0.1 that leads to Information Disclosu... |
| CVE-2022-38484 | HIGH | 8.8 | 1.6% | Oct 25, 2023 | An arbitrary file upload and directory traversal vulnerability exist in the file upload functionality of the System Setu... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now