2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20449 | MEDIUM | 4.4 | 0.1% | Dec 13, 2022 | In writeApplicationRestrictionsLAr of UserManagerService.java, there is a possible overwrite of system files due to a pa... |
| CVE-2022-20444 | — | — | — | Dec 13, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-20442 | HIGH | 7.3 | 0.1% | Dec 13, 2022 | In onCreate of ReviewPermissionsActivity.java, there is a possible way to grant permissions for a separate app with API ... |
| CVE-2022-20411 | HIGH | 8.8 | 1.9% | Dec 13, 2022 | In avdt_msg_asmbl of avdt_msg.cc, there is a possible out of bounds write due to a missing bounds check. This could lead... |
| CVE-2022-20240 | LOW | 2.3 | 0.1% | Dec 13, 2022 | In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a miss... |
| CVE-2022-46363 | HIGH | 7.5 | 1.2% | Dec 13, 2022 | A vulnerability in Apache CXF before versions 3.5.5 and 3.4.10 allows an attacker to perform a remote directory listing ... |
| CVE-2022-46059 | MEDIUM | 6.5 | 0.3% | Dec 13, 2022 | AeroCMS v0.0.1 is vulnerable to Cross Site Request Forgery (CSRF). |
| CVE-2022-45871 | HIGH | 7.5 | 0.4% | Dec 13, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in the fsicapd component used in WithSecure products whereby the ... |
| CVE-2022-45693 | HIGH | 7.5 | 1.4% | Dec 13, 2022 | Jettison before v1.5.2 was discovered to contain a stack overflow via the map parameter. This vulnerability allows attac... |
| CVE-2022-45690 | HIGH | 7.5 | 0.9% | Dec 13, 2022 | A stack overflow in the org.json.JSONTokener.nextValue::JSONTokener.java component of hutool-json v5.8.10 allows attacke... |
| CVE-2022-45689 | HIGH | 7.5 | 0.8% | Dec 13, 2022 | hutool-json v5.8.10 was discovered to contain an out of memory error. |
| CVE-2022-45688 | HIGH | 7.5 | 1.2% | Dec 13, 2022 | A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service ... |
| CVE-2022-45685 | HIGH | 7.5 | 1.4% | Dec 13, 2022 | A stack overflow in Jettison before v1.5.2 allows attackers to cause a Denial of Service (DoS) via crafted JSON data. |
| CVE-2022-44636 | MEDIUM | 4.6 | 0.2% | Dec 13, 2022 | The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spo... |
| CVE-2022-44303 | MEDIUM | 6.1 | 0.6% | Dec 13, 2022 | Resque Scheduler version 1.27.4 is vulnerable to Cross-site scripting (XSS). A remote attacker could inject javascript c... |
| CVE-2022-29580 | HIGH | 7.8 | 0.4% | Dec 13, 2022 | There exists a path traversal vulnerability in the Android Google Search app. This is caused by the incorrect usage of u... |
| CVE-2022-46061 | MEDIUM | 6.1 | 0.5% | Dec 13, 2022 | AeroCMS v0.0.1 is vulnerable to ClickJacking. |
| CVE-2022-46058 | MEDIUM | 4.8 | 0.5% | Dec 13, 2022 | AeroCMS v0.0.1 was discovered to contain a cross-site scripting (XSS) vulnerability via add_post.php. This vulnerability... |
| CVE-2022-46047 | MEDIUM | 4.9 | 0.8% | Dec 13, 2022 | AeroCMS v0.0.1 is vulnerable to SQL Injection via the delete parameter. |
| CVE-2022-38124 | MEDIUM | 6.5 | 0.5% | Dec 13, 2022 | Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner. |
| CVE-2022-4446 | CRITICAL | 9.8 | 1.3% | Dec 13, 2022 | PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0. |
| CVE-2022-4444 | MEDIUM | 6.1 | 0.5% | Dec 13, 2022 | A vulnerability was found in ipti br.tag. It has been declared as problematic. Affected by this vulnerability is an unkn... |
| CVE-2022-4098 | HIGH | 8 | 0.3% | Dec 13, 2022 | Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass through IP spoofing. Aft... |
| CVE-2022-23523 | MEDIUM | 5.5 | 0.2% | Dec 13, 2022 | In versions prior to 0.8.1, the linux-loader crate uses the offsets and sizes provided in the ELF headers to determine t... |
| CVE-2022-23505 | HIGH | 7.5 | 0.8% | Dec 13, 2022 | Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prio... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now