2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-25882 | HIGH | 7.5 | 1.6% | Jan 26, 2023 | Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tenso... |
| CVE-2022-25860 | CRITICAL | 9.8 | 2.7% | Jan 26, 2023 | Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), ... |
| CVE-2022-25847 | MEDIUM | 6.1 | 0.6% | Jan 26, 2023 | All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to... |
| CVE-2022-25350 | HIGH | 7.8 | 1.2% | Jan 26, 2023 | All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper ... |
| CVE-2022-22462 | HIGH | 7.5 | 0.5% | Jan 26, 2023 | IBM Security Verify Governance, Identity Manager virtual appliance component 10.0.1 uses weaker than expected cryptogra... |
| CVE-2022-21810 | HIGH | 7.8 | 1.2% | Jan 26, 2023 | All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanit... |
| CVE-2022-21192 | HIGH | 7.5 | 1.3% | Jan 26, 2023 | All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other ... |
| CVE-2022-20494 | MEDIUM | 5.5 | 0.4% | Jan 26, 2023 | In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could ... |
| CVE-2022-20493 | HIGH | 7.8 | 0.2% | Jan 26, 2023 | In Condition of Condition.java, there is a possible way to grant notification access due to improper input validation. T... |
| CVE-2022-20492 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource ... |
| CVE-2022-20490 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | In multiple functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resou... |
| CVE-2022-20489 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource ... |
| CVE-2022-20461 | HIGH | 7.8 | 0.1% | Jan 26, 2023 | In pinReplyNative of com_android_bluetooth_btservice_AdapterService.cpp, there is a possible out of bounds read due to t... |
| CVE-2022-20458 | MEDIUM | 5.5 | 0.1% | Jan 26, 2023 | The logs of sensitive information (PII) or hardware identifier should only be printed in Android "userdebug" or "eng" bu... |
| CVE-2022-20456 | HIGH | 7.8 | 0.2% | Jan 26, 2023 | In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resourc... |
| CVE-2022-20235 | MEDIUM | 5.5 | 0.1% | Jan 26, 2023 | The PowerVR GPU kernel driver maintains an "Information Page" used by its cache subsystem. This page can only be written... |
| CVE-2022-20215 | MEDIUM | 5.5 | 0.1% | Jan 26, 2023 | In onCreate of MasterClearConfirmFragment.java, there is a possible factory reset due to a tapjacking/overlay attack. Th... |
| CVE-2022-20214 | MEDIUM | 4.7 | 0.2% | Jan 26, 2023 | In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overl... |
| CVE-2022-20213 | MEDIUM | 5.5 | 0.1% | Jan 26, 2023 | In ApplicationsDetailsActivity of AndroidManifest.xml, there is a possible DoS due to a tapjacking/overlay attack. This ... |
| CVE-2022-1892 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local p... |
| CVE-2022-1891 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local p... |
| CVE-2022-1890 | HIGH | 7.8 | 0.3% | Jan 26, 2023 | A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privilege... |
| CVE-2022-42423 | HIGH | 7.8 | 0.4% | Jan 26, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us... |
| CVE-2022-42421 | HIGH | 7.8 | 0.4% | Jan 26, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us... |
| CVE-2022-42420 | HIGH | 7.8 | 0.4% | Jan 26, 2023 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. Us... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now