2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20119 | MEDIUM | 5.5 | 0.1% | May 10, 2022 | In private_handle_t of mali_gralloc_buffer.h, there is a possible information disclosure due to uninitialized data. This... |
| CVE-2022-20117 | MEDIUM | 5.5 | 0.1% | May 10, 2022 | In (TBD) of (TBD), there is a possible way to decrypt local data encrypted by the GSC due to improperly used crypto. Thi... |
| CVE-2022-1431 | MEDIUM | 5.3 | 1.4% | May 10, 2022 | An issue has been discovered in GitLab affecting all versions starting from 12.10 before 14.8.6, all versions starting f... |
| CVE-2022-1417 | MEDIUM | 4.3 | 0.9% | May 10, 2022 | Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting f... |
| CVE-2022-0866 | MEDIUM | 5.3 | 0.8% | May 10, 2022 | This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an ... |
| CVE-2022-30278 | MEDIUM | 6.1 | 0.8% | May 10, 2022 | A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote atta... |
| CVE-2022-20115 | MEDIUM | 5.5 | 0.1% | May 10, 2022 | In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information wit... |
| CVE-2022-20112 | MEDIUM | 5.5 | 0.1% | May 10, 2022 | In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change priv... |
| CVE-2022-20011 | MEDIUM | 5.5 | 0.1% | May 10, 2022 | In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to mi... |
| CVE-2022-20010 | MEDIUM | 6.5 | 0.3% | May 10, 2022 | In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to an incorrect bounds check. This c... |
| CVE-2022-20009 | MEDIUM | 6.8 | 0.3% | May 10, 2022 | In various functions of the USB gadget subsystem, there is a possible out of bounds write due to a missing bounds check.... |
| CVE-2022-20008 | MEDIUM | 4.6 | 0.4% | May 10, 2022 | In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This co... |
| CVE-2022-1567 | MEDIUM | 6.1 | 1.1% | May 10, 2022 | The WP-JS plugin for WordPress contains a script called wp-js.php with the function wp_js_admin, that accepts unvalidate... |
| CVE-2022-1476 | MEDIUM | 6.5 | 47.5% | May 10, 2022 | The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to... |
| CVE-2022-1209 | MEDIUM | 5.4 | 0.7% | May 10, 2022 | The Ultimate Member plugin for WordPress is vulnerable to arbitrary redirects due to insufficient validation on supplied... |
| CVE-2022-1649 | MEDIUM | 5.5 | 0.7% | May 10, 2022 | Null pointer dereference in libr/bin/format/mach0/mach0.c in radareorg/radare2 in GitHub repository radareorg/radare2 pr... |
| CVE-2022-24041 | MEDIUM | 6.5 | 0.4% | May 10, 2022 | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.... |
| CVE-2022-24040 | MEDIUM | 6.5 | 0.8% | May 10, 2022 | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.... |
| CVE-2022-29868 | MEDIUM | 5.5 | 0.2% | May 9, 2022 | 1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software runn... |
| CVE-2022-27308 | MEDIUM | 5.4 | 2.5% | May 9, 2022 | A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrar... |
| CVE-2022-28161 | MEDIUM | 5.5 | 0.2% | May 9, 2022 | An information exposure through log file vulnerability in Brocade SANNav versions before Brocade SANnav 2.2.0 could allo... |
| CVE-2022-27114 | MEDIUM | 5.5 | 0.9% | May 9, 2022 | There is a vulnerability in htmldoc 1.9.16. In image_load_jpeg function image.cxx when it calls malloc,'img->width' and ... |
| CVE-2022-22481 | MEDIUM | 5.3 | 1.1% | May 9, 2022 | IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain access to the web inter... |
| CVE-2022-22319 | MEDIUM | 5.4 | 0.9% | May 9, 2022 | IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could ... |
| CVE-2022-1338 | MEDIUM | 4.8 | 0.6% | May 9, 2022 | The Easily Generate Rest API Url WordPress plugin through 1.0.0 does not escape some of its settings, allowing high priv... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now