2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-22099HIGH7.8Memory corruption in multimedia due to improper validation of array index in Snapdragon Auto
CVE-2022-22098HIGH7.8Memory corruption in multimedia driver due to untrusted pointer dereference while reading data from socket in Snapdragon...
CVE-2022-22097HIGH7.8Memory corruption in graphic driver due to use after free while calling multiple threads application to driver. in Snapd...
CVE-2022-22080HIGH7.8Improper validation of backend id in PCM routing process can lead to memory corruption in Snapdragon Auto, Snapdragon Co...
CVE-2022-22070HIGH7.8Memory corruption in audio due to lack of check of invalid routing address into APR Routing table in Snapdragon Auto, Sn...
CVE-2022-22069HIGH7.8Devices with keyprotect off may store unencrypted keybox in RPMB and cause cryptographic issue in Snapdragon Auto, Snapd...
CVE-2022-22067HIGH7.8Potential memory leak in modem during the processing of NSA RRC Reconfiguration with invalid Radio Bearer Config in Snap...
CVE-2022-22061HIGH7.8Out of bounds writing is possible while verifying device IDs due to improper length check before copying the data in Sna...
CVE-2022-22059HIGH7.8Memory corruption due to out of bound read while parsing a video file in Snapdragon Auto, Snapdragon Compute, Snapdragon...
CVE-2022-29158HIGH7.5Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles ...
CVE-2022-25813HIGH7.5In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can ins...
CVE-2022-39189HIGH7.8An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromis...
CVE-2022-36636HIGH8.8Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php...
CVE-2022-39177HIGH8.8BlueZ before 5.59 allows physically proximate attackers to cause a denial of service because malformed and invalid capab...
CVE-2022-39176HIGH8.8BlueZ before 5.59 allows physically proximate attackers to obtain sensitive information because profiles/audio/avrcp.c d...
CVE-2022-39170HIGH8.8libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
CVE-2022-36622HIGH7.5Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_...
CVE-2022-36621HIGH7.5Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_...
CVE-2022-36604HIGH7.5An access control issue in Canaan Avalon ASIC Miner 2020.3.30 and below allows unauthenticated attackers to arbitrarily ...
CVE-2022-36603HIGH8.8InnoSilicon T3T+ t2t+_soc_20190911_151433.swu was discovered to contain a remote code execution (RCE) vulnerability in t...
CVE-2022-36602HIGH8.8InnoSilicon A10 a10_20200924_120556 was discovered to contain a remote code execution (RCE) vulnerability in the setPlat...
CVE-2022-32743HIGH7.5Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged ...
CVE-2022-2738HIGH7.5The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrec...
CVE-2022-2639HIGH7.8An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, whil...
CVE-2022-2320HIGH7.8A flaw was found in the Xorg-x11-server. The specific flaw exists within the handling of ProcXkbSetDeviceInfo requests. ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now