2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-30580 | HIGH | 7.8 | 0.6% | Aug 10, 2022 | Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working d... |
| CVE-2022-2458 | HIGH | 8.2 | 0.7% | Aug 10, 2022 | XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's process... |
| CVE-2022-29804 | HIGH | 7.5 | 1.9% | Aug 10, 2022 | Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and G... |
| CVE-2022-28881 | HIGH | 7.5 | 0.4% | Aug 10, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the aerdl.dll component used in certai... |
| CVE-2022-28131 | HIGH | 7.5 | 1.9% | Aug 10, 2022 | Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a pan... |
| CVE-2022-25793 | HIGH | 7.8 | 0.3% | Aug 10, 2022 | A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through ... |
| CVE-2022-20360 | HIGH | 7.8 | 0.2% | Aug 10, 2022 | In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escal... |
| CVE-2022-20356 | HIGH | 7.8 | 0.1% | Aug 10, 2022 | In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service ... |
| CVE-2022-20354 | HIGH | 7.8 | 0.1% | Aug 10, 2022 | In onDefaultNetworkChanged of Vpn.java, there is a possible way to disable VPN due to a logic error in the code. This co... |
| CVE-2022-20349 | HIGH | 7.8 | 0.1% | Aug 10, 2022 | In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction byp... |
| CVE-2022-20348 | HIGH | 7.8 | 0.1% | Aug 10, 2022 | In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass du... |
| CVE-2022-20347 | HIGH | 8.8 | 0.8% | Aug 10, 2022 | In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. Th... |
| CVE-2022-20345 | HIGH | 8.8 | 0.4% | Aug 10, 2022 | In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This cou... |
| CVE-2022-20344 | HIGH | 7 | 0.1% | Aug 10, 2022 | In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communication due to a race... |
| CVE-2022-35715 | HIGH | 7.5 | 0.8% | Aug 10, 2022 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec... |
| CVE-2022-33930 | HIGH | 7.5 | 0.5% | Aug 10, 2022 | Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could pot... |
| CVE-2022-33928 | HIGH | 8.8 | 0.3% | Aug 10, 2022 | Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with... |
| CVE-2022-22369 | HIGH | 7.1 | 0.2% | Aug 10, 2022 | IBM Workload Scheduler 9.4 and 9.5 could allow a local user to overwrite key system files which would cause the system t... |
| CVE-2022-20866 | HIGH | 7.5 | 17.2% | Aug 10, 2022 | A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisc... |
| CVE-2022-0028 | HIGH | 8.6 | 2.0% | Aug 10, 2022 | A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified T... |
| CVE-2022-36324 | HIGH | 7.5 | 1.4% | Aug 10, 2022 | Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated rem... |
| CVE-2022-34661 | HIGH | 7.5 | 0.6% | Aug 10, 2022 | A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V1... |
| CVE-2022-20816 | HIGH | 8.1 | 1.1% | Aug 10, 2022 | A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni... |
| CVE-2022-20792 | HIGH | 7.8 | 0.5% | Aug 10, 2022 | A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0.104... |
| CVE-2022-31780 | HIGH | 7.5 | 1.8% | Aug 10, 2022 | Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now