2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3886 | HIGH | 8.8 | 0.6% | Nov 9, 2022 | Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially e... |
| CVE-2022-3885 | HIGH | 8.8 | 0.7% | Nov 9, 2022 | Use after free in V8 in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2022-39328 | HIGH | 8.1 | 0.9% | Nov 8, 2022 | Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 co... |
| CVE-2022-41214 | HIGH | 8.7 | 0.7% | Nov 8, 2022 | Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with hi... |
| CVE-2022-41211 | HIGH | 7.8 | 0.3% | Nov 8, 2022 | Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D ... |
| CVE-2022-41203 | HIGH | 8.8 | 0.9% | Nov 8, 2022 | In some workflow of SAP BusinessObjects BI Platform (Central Management Console and BI LaunchPad), an authenticated atta... |
| CVE-2022-39386 | HIGH | 7.5 | 0.7% | Nov 8, 2022 | @fastify/websocket provides WebSocket support for Fastify. Any application using @fastify/websocket could crash if a spe... |
| CVE-2022-20462 | HIGH | 7.8 | 0.1% | Nov 8, 2022 | In phNxpNciHal_write_unlocked of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. ... |
| CVE-2022-20452 | HIGH | 7.8 | 0.4% | Nov 8, 2022 | In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused ... |
| CVE-2022-20451 | HIGH | 7.8 | 0.1% | Nov 8, 2022 | In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission ch... |
| CVE-2022-20450 | HIGH | 7.8 | 0.1% | Nov 8, 2022 | In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a ... |
| CVE-2022-20445 | HIGH | 7.5 | 0.4% | Nov 8, 2022 | In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validati... |
| CVE-2022-20441 | HIGH | 7.8 | 0.1% | Nov 8, 2022 | In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the... |
| CVE-2022-32601 | HIGH | 7.8 | 0.1% | Nov 8, 2022 | In telephony, there is a possible permission bypass due to a parcel format mismatch. This could lead to local escalation... |
| CVE-2022-26446 | HIGH | 7.5 | 1.1% | Nov 8, 2022 | In Modem 4G RRC, there is a possible system crash due to improper input validation. This could lead to remote denial of ... |
| CVE-2022-39377 | HIGH | 7.8 | 1.1% | Nov 8, 2022 | sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and n... |
| CVE-2022-44741 | HIGH | 8.8 | 0.3% | Nov 8, 2022 | Cross-Site Request Forgery (CSRF) vulnerability leading to Cross-Site Scripting (XSS) in David Anderson Testimonial Slid... |
| CVE-2022-41136 | HIGH | 8.8 | 0.3% | Nov 8, 2022 | Cross-Site Request Forgery (CSRF) vulnerability leading to Stored Cross-Site Scripting (XSS) in Vladimir Anokhin's Short... |
| CVE-2022-38137 | HIGH | 8.8 | 0.3% | Nov 8, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress. |
| CVE-2022-44556 | HIGH | 7.5 | 0.4% | Nov 8, 2022 | Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availabili... |
| CVE-2022-44311 | HIGH | 8.1 | 1.1% | Nov 8, 2022 | html2xhtml v1.3 was discovered to contain an Out-Of-Bounds read in the function static void elm_close(tree_node_t *nodo)... |
| CVE-2022-43343 | HIGH | 7.5 | 1.1% | Nov 8, 2022 | N-Prolog v1.91 was discovered to contain a global buffer overflow vulnerability in the function gettoken() at Main.c. |
| CVE-2022-41757 | HIGH | 8.8 | 0.7% | Nov 8, 2022 | An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operat... |
| CVE-2022-43958 | HIGH | 7.6 | 0.3% | Nov 8, 2022 | A vulnerability has been identified in QMS Automotive (All versions < V12.39), QMS Automotive (All versions < V12.39). U... |
| CVE-2022-43546 | HIGH | 8.8 | 1.5% | Nov 8, 2022 | A vulnerability has been identified in POWER METER SICAM Q100 (All versions < V2.50), POWER METER SICAM Q100 (All versio... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now