2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-20449MEDIUM4.4In writeApplicationRestrictionsLAr of UserManagerService.java, there is a possible overwrite of system files due to a pa...
CVE-2022-20444Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-20442HIGH7.3In onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API ...
CVE-2022-20411HIGH8.8In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead...
CVE-2022-20240LOW2.3In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a miss...
CVE-2022-46363HIGH7.5A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing ...
CVE-2022-46059MEDIUM6.5AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF).
CVE-2022-45871HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the ...
CVE-2022-45693HIGH7.5Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attac...
CVE-2022-45690HIGH7.5A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attacke...
CVE-2022-45689HIGH7.5hutool-json v5.8.10 was discovered to contain an out of memory error.
CVE-2022-45688HIGH7.5A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service ...
CVE-2022-45685HIGH7.5A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data.
CVE-2022-44636MEDIUM4.6The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spo...
CVE-2022-44303MEDIUM6.1Resque Scheduler version 1.27.4 is vulnerable to Cross-site scripting (XSS). A remote attacker could inject javascript c...
CVE-2022-29580HIGH7.8There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of u...
CVE-2022-46061MEDIUM6.1AeroCMS v0.0.1 is vulnerable to ClickJacking.
CVE-2022-46058MEDIUM4.8AeroCMS v0.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability...
CVE-2022-46047MEDIUM4.9AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter.
CVE-2022-38124MEDIUM6.5Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.
CVE-2022-4446CRITICAL9.8PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.
CVE-2022-4444MEDIUM6.1A vulnerability was found in ipti br.tag. It has been declared as problematic. Affected by this vulnerability is an unkn...
CVE-2022-4098HIGH8Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. Aft...
CVE-2022-23523MEDIUM5.5In versions prior to 0.8.1, the linux-loader crate uses the offsets and sizes provided in the ELF headers to determine t...
CVE-2022-23505HIGH7.5Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prio...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now