2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-25783MEDIUM4.3Insufficient Logging vulnerability in web server of Secomea GateManager allows logged in user to issue improper queries ...
CVE-2022-25782MEDIUM5.4Improper Handling of Insufficient Privileges vulnerability in Web UI of Secomea GateManager allows logged in user to acc...
CVE-2022-25781MEDIUM6.1Cross-site Scripting (XSS) vulnerability in Web UI of Secomea GateManager allows phishing attacker to inject javascript ...
CVE-2022-25780MEDIUM4.3Information Exposure vulnerability in web UI of Secomea GateManager allows logged in user to query devices outside own s...
CVE-2022-25779MEDIUM4.3Logging of Excessive Data vulnerability in audit log of Secomea GateManager allows logged in user to write text entries ...
CVE-2022-1571MEDIUM6.1Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. Th...
CVE-2022-1555MEDIUM6.1DOM XSS in microweber ver 1.2.15 in GitHub repository microweber/microweber prior to 1.2.16. inject arbitrary js code, d...
CVE-2022-1502MEDIUM4.3Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be ...
CVE-2022-20108MEDIUM6.7In voice service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local...
CVE-2022-20107MEDIUM4.4In subtitle service, there is a possible application crash due to an integer overflow. This could lead to local denial o...
CVE-2022-20106MEDIUM6.7In MM service, there is a possible out of bounds write due to a heap-based buffer overflow. This could lead to local esc...
CVE-2022-20105MEDIUM6.7In MM service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local es...
CVE-2022-20104MEDIUM5.5In aee daemon, there is a possible information disclosure due to improper access control. This could lead to local infor...
CVE-2022-20103MEDIUM4.4In aee daemon, there is a possible information disclosure due to symbolic link following. This could lead to local infor...
CVE-2022-20102MEDIUM4.4In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local in...
CVE-2022-20101MEDIUM5.5In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information ...
CVE-2022-28793MEDIUM4.4Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to...
CVE-2022-28791MEDIUM5.5Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to ove...
CVE-2022-28789MEDIUM5.5Unprotected activities in Voice Note prior to version 21.3.51.11 allows attackers to record voice without user interacti...
CVE-2022-28788MEDIUM5.5Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leadi...
CVE-2022-28787MEDIUM5.5Improper buffer size check logic in wmfextractor library prior to SMR May-2022 Release 1 allows out of bounds read leadi...
CVE-2022-28786MEDIUM5.5Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leadi...
CVE-2022-28785MEDIUM5.5Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leadi...
CVE-2022-28782MEDIUM4.6Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to ...
CVE-2022-28781MEDIUM6.7Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now