2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-30580HIGH7.8Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working d...
CVE-2022-2458HIGH8.2XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's process...
CVE-2022-29804HIGH7.5Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and G...
CVE-2022-28881HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the aerdl.dll component used in certai...
CVE-2022-28131HIGH7.5Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a pan...
CVE-2022-25793HIGH7.8A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through ...
CVE-2022-20360HIGH7.8In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escal...
CVE-2022-20356HIGH7.8In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service ...
CVE-2022-20354HIGH7.8In onDefaultNetworkChanged of Vpn.java, there is a possible way to disable VPN due to a logic error in the code. This co...
CVE-2022-20349HIGH7.8In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction byp...
CVE-2022-20348HIGH7.8In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass du...
CVE-2022-20347HIGH8.8In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. Th...
CVE-2022-20345HIGH8.8In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This cou...
CVE-2022-20344HIGH7In stealReceiveChannel of EventThread.cpp, there is a possible way to interfere with process communication due to a race...
CVE-2022-35715HIGH7.5IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec...
CVE-2022-33930HIGH7.5Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could pot...
CVE-2022-33928HIGH8.8Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with...
CVE-2022-22369HIGH7.1IBM Workload Scheduler 9.4 and 9.5 could allow a local user to overwrite key system files which would cause the system t...
CVE-2022-20866HIGH7.5A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisc...
CVE-2022-0028HIGH8.6A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified T...
CVE-2022-36324HIGH7.5Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated rem...
CVE-2022-34661HIGH7.5A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V1...
CVE-2022-20816HIGH8.1A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni...
CVE-2022-20792HIGH7.8A vulnerability in the regex module used by the signature database load module of Clam AntiVirus (ClamAV) versions 0.104...
CVE-2022-31780HIGH7.5Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now