2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20113 | HIGH | 7.8 | 0.2% | May 10, 2022 | In mPreference of DefaultUsbConfigurationPreferenceController.java, there is a possible way to enable file transfer mode... |
| CVE-2022-20007 | HIGH | 7 | 0.2% | May 10, 2022 | In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app th... |
| CVE-2022-20006 | HIGH | 7 | 0.1% | May 10, 2022 | In several functions of KeyguardServiceWrapper.java and related files,, there is a possible way to briefly view what's u... |
| CVE-2022-20005 | HIGH | 7.8 | 0.2% | May 10, 2022 | In validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch between running code and... |
| CVE-2022-20004 | HIGH | 7.8 | 0.2% | May 10, 2022 | In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input valida... |
| CVE-2022-1505 | HIGH | 7.5 | 1.8% | May 10, 2022 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame... |
| CVE-2022-1463 | HIGH | 8.8 | 1.7% | May 10, 2022 | The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode ... |
| CVE-2022-1453 | HIGH | 7.5 | 6.9% | May 10, 2022 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame... |
| CVE-2022-1442 | HIGH | 7.5 | 9.1% | May 10, 2022 | The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/c... |
| CVE-2022-28986 | HIGH | 7.5 | 2.9% | May 10, 2022 | LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object reference... |
| CVE-2022-23677 | HIGH | 8.1 | 19.1% | May 10, 2022 | A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 1... |
| CVE-2022-22454 | HIGH | 7.8 | 0.3% | May 10, 2022 | IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the... |
| CVE-2022-26988 | HIGH | 7.8 | 1.4% | May 10, 2022 | TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow ... |
| CVE-2022-26987 | HIGH | 7.8 | 1.4% | May 10, 2022 | TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow ... |
| CVE-2022-1629 | HIGH | 7.8 | 1.8% | May 10, 2022 | Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are ca... |
| CVE-2022-1621 | HIGH | 7.8 | 2.3% | May 10, 2022 | Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capa... |
| CVE-2022-1537 | HIGH | 7 | 0.3% | May 10, 2022 | file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repo... |
| CVE-2022-1397 | HIGH | 8.8 | 1.1% | May 10, 2022 | API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Full system takeover. |
| CVE-2022-23705 | HIGH | 7.5 | 1.0% | May 9, 2022 | A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arr... |
| CVE-2022-23704 | HIGH | 7.5 | 1.8% | May 9, 2022 | A potential security vulnerability has been identified in Integrated Lights-Out 4 (iLO 4). The vulnerability could allow... |
| CVE-2022-30524 | HIGH | 7.8 | 1.6% | May 9, 2022 | There is an invalid memory access in the TextLine class in TextOutputDev.cc in Xpdf 4.0.4 because the text extractor mis... |
| CVE-2022-30240 | HIGH | 7.8 | 0.5% | May 9, 2022 | An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift... |
| CVE-2022-30239 | HIGH | 7.8 | 0.5% | May 9, 2022 | An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena J... |
| CVE-2022-29972 | HIGH | 7.8 | 3.7% | May 9, 2022 | An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift... |
| CVE-2022-29971 | HIGH | 7.8 | 0.3% | May 9, 2022 | An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Athena O... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now