2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-48454MEDIUM5.5In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial ...
CVE-2022-3007HIGH8.1The vulnerability exists in Syska SW100 Smartwatch due to an improper implementation and/or configuration of Nordic Devi...
CVE-2022-39172MEDIUM5.4A stored XSS in the process overview (bersicht zugewiesener Vorgaenge) in mbsupport openVIVA c2 20220101 allows a remote...
CVE-2022-20264MEDIUM5.5In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due ...
CVE-2022-4575MEDIUM6.7 A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models cou...
CVE-2022-4574MEDIUM6.7 An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local ac...
CVE-2022-4573MEDIUM6.7 An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access a...
CVE-2022-48189MEDIUM6.7An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local acce...
CVE-2022-48190Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2022-34834MEDIUM4.8An issue was discovered in VERMEG AgileReporter 21.3. Attackers can gain privileges via an XSS payload in an Add Comment...
CVE-2022-34833MEDIUM5.4An issue was discovered in VERMEG AgileReporter 21.3. An admin can enter an XSS payload in the Analysis component.
CVE-2022-34832MEDIUM6.5An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component.
CVE-2022-3702HIGH7.1 A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that c...
CVE-2022-3701HIGH7.8 A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlie...
CVE-2022-3700MEDIUM6.3A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0....
CVE-2022-3681MEDIUM6.5A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range o...
CVE-2022-3611HIGH7.5An information disclosure vulnerability has been identified in the Lenovo App Store which may allow some applications to...
CVE-2022-3429MEDIUM6.5A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malform...
CVE-2022-34887MEDIUM5.4Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers with...
CVE-2022-34886HIGH8.8A remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a r...
CVE-2022-4886MEDIUM6.5Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.
CVE-2022-3699HIGH7.8 A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo ...
CVE-2022-3698MEDIUM4.4 A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and  Len...
CVE-2022-38485MEDIUM6.5A directory traversal vulnerability exists in the AgeVolt Portal prior to version 0.1 that leads to Information Disclosu...
CVE-2022-38484HIGH8.8An arbitrary file upload and directory traversal vulnerability exist in the file upload functionality of the System Setu...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now