2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-32592MEDIUM6.7In cpu dvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation ...
CVE-2022-32590MEDIUM6.7In wlan, there is a possible use after free due to an incorrect status check. This could lead to local escalation of pri...
CVE-2022-26475MEDIUM6.7In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p...
CVE-2022-26474MEDIUM6.7In sensorhub, there is a possible out of bounds write due to an incorrect calculation of buffer size. This could lead to...
CVE-2022-26473MEDIUM6.7In vdec fmt, there is a possible use after free due to improper locking. This could lead to local escalation of privileg...
CVE-2022-26452MEDIUM6.7In isp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege wit...
CVE-2022-41392MEDIUM5.4A cross-site scripting (XSS) vulnerability in TotalJS commit 8c2c8909 allows attackers to execute arbitrary web scripts ...
CVE-2022-37896MEDIUM6.1A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow a remote attacker to conduct ...
CVE-2022-37895MEDIUM4.9An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba Instant...
CVE-2022-37894MEDIUM6.5An unauthenticated Denial of Service (DoS) vulnerability exists in the handling of certain SSID strings by Aruba Instant...
CVE-2022-41414MEDIUM5.3An insecure default in the component auth.login.prompt.enabled of Liferay Portal v7.0.0 through v7.4.2 allows attackers ...
CVE-2022-37892MEDIUM5.4A vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface could allow an unauthenticated remote att...
CVE-2022-21936MEDIUM6.5On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providi...
CVE-2022-41291MEDIUM6.5IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user ...
CVE-2022-36772MEDIUM6.5IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should onl...
CVE-2022-34308MEDIUM5.5IBM CICS TX 11.1 could allow a local user to cause a denial of service due to improper load handling. IBM X-Force ID: 22...
CVE-2022-30613MEDIUM5.5IBM QRadar SIEM 7.4 and 7.5 could disclose sensitive information via a local service to a privileged user. IBM X-Force I...
CVE-2022-39878MEDIUM5.5Improper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive...
CVE-2022-39877MEDIUM5.3Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S...
CVE-2022-39875MEDIUM4.4Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized ...
CVE-2022-39874MEDIUM5.5Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthori...
CVE-2022-39873MEDIUM4.6Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add boo...
CVE-2022-39863MEDIUM4.7Intent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to access content provid...
CVE-2022-39857MEDIUM5.5Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers ...
CVE-2022-39855MEDIUM4.3Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to con...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now