2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31674 | MEDIUM | 4.3 | 0.5% | Aug 10, 2022 | VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with netwo... |
| CVE-2022-2719 | MEDIUM | 5.5 | 0.3% | Aug 10, 2022 | In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/oper... |
| CVE-2022-23238 | MEDIUM | 6.5 | 0.6% | Aug 10, 2022 | Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux ... |
| CVE-2022-22983 | MEDIUM | 5.9 | 0.3% | Aug 10, 2022 | VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious acto... |
| CVE-2022-20357 | MEDIUM | 5.5 | 0.1% | Aug 10, 2022 | In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could... |
| CVE-2022-20355 | MEDIUM | 5.5 | 0.1% | Aug 10, 2022 | In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could le... |
| CVE-2022-20353 | MEDIUM | 5.5 | 0.1% | Aug 10, 2022 | In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input v... |
| CVE-2022-20352 | MEDIUM | 5.5 | 0.1% | Aug 10, 2022 | In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request lo... |
| CVE-2022-20350 | MEDIUM | 5.5 | 0.1% | Aug 10, 2022 | In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notific... |
| CVE-2022-20346 | MEDIUM | 6.5 | 0.4% | Aug 10, 2022 | In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds read due to an incor... |
| CVE-2022-1962 | MEDIUM | 5.5 | 0.9% | Aug 10, 2022 | Uncontrolled recursion in the Parse functions in go/parser before Go 1.17.12 and Go 1.18.4 allow an attacker to cause a ... |
| CVE-2022-1705 | MEDIUM | 6.5 | 1.1% | Aug 10, 2022 | Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 al... |
| CVE-2022-34365 | MEDIUM | 6.5 | 0.7% | Aug 10, 2022 | WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability,... |
| CVE-2022-33931 | MEDIUM | 5.3 | 0.4% | Aug 10, 2022 | Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An attacker with no ... |
| CVE-2022-33929 | MEDIUM | 6.1 | 0.4% | Aug 10, 2022 | Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in EndUserSummary pag... |
| CVE-2022-33927 | MEDIUM | 6.5 | 0.4% | Aug 10, 2022 | Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could e... |
| CVE-2022-33926 | MEDIUM | 6.5 | 0.4% | Aug 10, 2022 | Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user co... |
| CVE-2022-33925 | MEDIUM | 6.5 | 0.7% | Aug 10, 2022 | Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authentica... |
| CVE-2022-33924 | MEDIUM | 5.3 | 0.4% | Aug 10, 2022 | Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability with which an attacker with... |
| CVE-2022-29090 | MEDIUM | 6.5 | 0.3% | Aug 10, 2022 | Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious ... |
| CVE-2022-22490 | MEDIUM | 4.9 | 0.7% | Aug 10, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot cr... |
| CVE-2022-22411 | MEDIUM | 6.5 | 0.5% | Aug 10, 2022 | IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow... |
| CVE-2022-20713 | MEDIUM | 6.1 | 1.7% | Aug 10, 2022 | A vulnerability in the VPN web client services component of Cisco Adaptive Security Appliance (ASA) Software and Cisco F... |
| CVE-2022-38133 | MEDIUM | 5.3 | 0.4% | Aug 10, 2022 | In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases |
| CVE-2022-2756 | MEDIUM | 6.5 | 2.3% | Aug 10, 2022 | Server-Side Request Forgery (SSRF) in GitHub repository kareadita/kavita prior to 0.5.4.1. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now