2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-20076 | MEDIUM | 4.4 | 0.1% | Apr 11, 2022 | In ged, there is a possible memory corruption due to an incorrect error handling. This could lead to local information d... |
| CVE-2022-20075 | MEDIUM | 6.7 | 0.1% | Apr 11, 2022 | In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privi... |
| CVE-2022-20074 | MEDIUM | 6.6 | 0.1% | Apr 11, 2022 | In preloader (partition), there is a possible out of bounds write due to a missing bounds check. This could lead to loca... |
| CVE-2022-20073 | MEDIUM | 6.6 | 0.2% | Apr 11, 2022 | In preloader (usb), there is a possible out of bounds write due to a integer underflow. This could lead to local escalat... |
| CVE-2022-20072 | MEDIUM | 6.7 | 0.3% | Apr 11, 2022 | In search engine service, there is a possible way to change the default search engine due to an incorrect comparison. Th... |
| CVE-2022-20071 | MEDIUM | 6.7 | 0.1% | Apr 11, 2022 | In ccu, there is a possible escalation of privilege due to a missing certificate validation. This could lead to local es... |
| CVE-2022-20070 | MEDIUM | 6.7 | 0.1% | Apr 11, 2022 | In ssmr, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of p... |
| CVE-2022-20069 | MEDIUM | 6.6 | 0.1% | Apr 11, 2022 | In preloader (usb), there is a possible out of bounds write due to an integer overflow. This could lead to local escalat... |
| CVE-2022-20068 | MEDIUM | 6.7 | 0.1% | Apr 11, 2022 | In mobile_log_d, there is a possible symbolic link following due to an improper link resolution. This could lead to loca... |
| CVE-2022-20067 | MEDIUM | 6.7 | 0.1% | Apr 11, 2022 | In mdp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr... |
| CVE-2022-20066 | MEDIUM | 4.4 | 0.1% | Apr 11, 2022 | In atf (hwfde), there is a possible leak of sensitive information due to incorrect error handling. This could lead to lo... |
| CVE-2022-20065 | MEDIUM | 6.7 | 0.1% | Apr 11, 2022 | In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disc... |
| CVE-2022-20064 | MEDIUM | 6.7 | 0.1% | Apr 11, 2022 | In ccci, there is a possible leak of kernel pointer due to an incorrect bounds check. This could lead to local informati... |
| CVE-2022-20063 | MEDIUM | 6.5 | 0.1% | Apr 11, 2022 | In atf (spm), there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation... |
| CVE-2022-20062 | MEDIUM | 6.7 | 0.1% | Apr 11, 2022 | In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege ... |
| CVE-2022-20052 | MEDIUM | 6.5 | 0.1% | Apr 11, 2022 | In mdp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege ... |
| CVE-2022-1193 | MEDIUM | 4.3 | 0.9% | Apr 11, 2022 | Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 al... |
| CVE-2022-1067 | MEDIUM | 6.5 | 0.8% | Apr 11, 2022 | Navigating to a specific URL with a patient ID number will result in the server generating a PDF of a lab report without... |
| CVE-2022-0835 | MEDIUM | 5.5 | 0.2% | Apr 11, 2022 | AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-pri... |
| CVE-2022-0552 | MEDIUM | 5.9 | 1.1% | Apr 11, 2022 | A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logg... |
| CVE-2022-27156 | MEDIUM | 5.4 | 0.5% | Apr 11, 2022 | Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection. |
| CVE-2022-27111 | MEDIUM | 5.4 | 0.5% | Apr 11, 2022 | Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend a... |
| CVE-2022-1007 | MEDIUM | 6.1 | 1.6% | Apr 11, 2022 | The Advanced Booking Calendar WordPress plugin before 1.7.1 does not sanitise and escape the room parameter before outpu... |
| CVE-2022-0969 | MEDIUM | 4.8 | 0.7% | Apr 11, 2022 | The Image optimization & Lazy Load by Optimole WordPress plugin before 3.3.2 does not sanitise and escape its "Lazyload ... |
| CVE-2022-0919 | MEDIUM | 5.3 | 1.1% | Apr 11, 2022 | The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper authorisation when searching boo... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now