2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2022-20113HIGH7.8In mPreference of DefaultUsbConfigurationPreferenceController.java, there is a possible way to enable file transfer mode...
CVE-2022-20007HIGH7In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app th...
CVE-2022-20006HIGH7In several functions of KeyguardServiceWrapper.java and related files,, there is a possible way to briefly view what's u...
CVE-2022-20005HIGH7.8In validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch between running code and...
CVE-2022-20004HIGH7.8In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input valida...
CVE-2022-1505HIGH7.5The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame...
CVE-2022-1463HIGH8.8The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode ...
CVE-2022-1453HIGH7.5The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame...
CVE-2022-1442HIGH7.5The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/c...
CVE-2022-28986HIGH7.5LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object reference...
CVE-2022-23677HIGH8.1A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 1...
CVE-2022-22454HIGH7.8IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the...
CVE-2022-26988HIGH7.8TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow ...
CVE-2022-26987HIGH7.8TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow ...
CVE-2022-1629HIGH7.8Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are ca...
CVE-2022-1621HIGH7.8Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capa...
CVE-2022-1537HIGH7file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repo...
CVE-2022-1397HIGH8.8API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Full system takeover.
CVE-2022-23705HIGH7.5A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arr...
CVE-2022-23704HIGH7.5A potential security vulnerability has been identified in Integrated Lights-Out 4 (iLO 4). The vulnerability could allow...
CVE-2022-30524HIGH7.8There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mis...
CVE-2022-30240HIGH7.8An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift...
CVE-2022-30239HIGH7.8An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena J...
CVE-2022-29972HIGH7.8An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift...
CVE-2022-29971HIGH7.8An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena O...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now