2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-25882HIGH7.5Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tenso...
CVE-2022-25860CRITICAL9.8Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), ...
CVE-2022-25847MEDIUM6.1All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to...
CVE-2022-25350HIGH7.8All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper ...
CVE-2022-22462HIGH7.5 IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker than expected cryptogra...
CVE-2022-21810HIGH7.8All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanit...
CVE-2022-21192HIGH7.5All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other ...
CVE-2022-20494MEDIUM5.5In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could ...
CVE-2022-20493HIGH7.8In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. T...
CVE-2022-20492HIGH7.8In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource ...
CVE-2022-20490HIGH7.8In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resou...
CVE-2022-20489HIGH7.8In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource ...
CVE-2022-20461HIGH7.8In pinReplyNative of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible out of bounds read due to t...
CVE-2022-20458MEDIUM5.5The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" bu...
CVE-2022-20456HIGH7.8In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resourc...
CVE-2022-20235MEDIUM5.5The PowerVR GPU kernel driver maintains an "Information Page" used by its cache subsystem. This page can only be written...
CVE-2022-20215MEDIUM5.5In onCreate of MasterClearConfirmFragment.java, there is a possible factory reset due to a tapjacking/overlay attack. Th...
CVE-2022-20214MEDIUM4.7In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overl...
CVE-2022-20213MEDIUM5.5In ApplicationsDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This ...
CVE-2022-1892HIGH7.8A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local p...
CVE-2022-1891HIGH7.8A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local p...
CVE-2022-1890HIGH7.8A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privilege...
CVE-2022-42423HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us...
CVE-2022-42421HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us...
CVE-2022-42420HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now