2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4949 | HIGH | 8.8 | 2.2% | Jun 7, 2023 | The AdSanity plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'aj... |
| CVE-2022-25834 | HIGH | 7.8 | 0.5% | Jun 7, 2023 | In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could ... |
| CVE-2022-40538 | HIGH | 7.5 | 0.4% | Jun 6, 2023 | Transient DOS due to reachable assertion in modem while processing sib with incorrect values from network. |
| CVE-2022-40536 | HIGH | 7.5 | 0.4% | Jun 6, 2023 | Transient DOS due to improper authentication in modem while receiving plain TLB OTA request message from network. |
| CVE-2022-40529 | HIGH | 7.8 | 0.1% | Jun 6, 2023 | Memory corruption due to improper access control in kernel while processing a mapping request from root process. |
| CVE-2022-40522 | HIGH | 7.8 | 0.1% | Jun 6, 2023 | Memory corruption in Linux Networking due to double free while handling a hyp-assign. |
| CVE-2022-40521 | HIGH | 7.5 | 0.4% | Jun 6, 2023 | Transient DOS due to improper authorization in Modem |
| CVE-2022-40507 | HIGH | 7.8 | 1.3% | Jun 6, 2023 | Memory corruption due to double free in Core while mapping HLOS address to the list. |
| CVE-2022-33307 | HIGH | 7.8 | 0.1% | Jun 6, 2023 | Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed. |
| CVE-2022-33267 | HIGH | 7.8 | 0.1% | Jun 6, 2023 | Memory corruption in Linux while sending DRM request. |
| CVE-2022-33264 | HIGH | 7.8 | 0.1% | Jun 6, 2023 | Memory corruption in modem due to stack based buffer overflow while parsing OTASP Key Generation Request Message. |
| CVE-2022-33263 | HIGH | 7.8 | 0.1% | Jun 6, 2023 | Memory corruption due to use after free in Core when multiple DCI clients register and deregister. |
| CVE-2022-33251 | HIGH | 7.5 | 0.4% | Jun 6, 2023 | Transient DOS due to reachable assertion in Modem because of invalid network configuration. |
| CVE-2022-33240 | HIGH | 7.8 | 0.1% | Jun 6, 2023 | Memory corruption in Audio due to incorrect type cast during audio use-cases. |
| CVE-2022-33230 | HIGH | 7.8 | 0.1% | Jun 6, 2023 | Memory corruption in FM Host due to buffer copy without checking the size of input in FM Host |
| CVE-2022-33227 | HIGH | 7.8 | 0.1% | Jun 6, 2023 | Memory corruption in Linux android due to double free while calling unregister provider after register call. |
| CVE-2022-33226 | HIGH | 7.8 | 0.1% | Jun 6, 2023 | Memory corruption due to buffer copy without checking the size of input in Core while processing ioctl commands from dia... |
| CVE-2022-33224 | HIGH | 7.8 | 0.1% | Jun 6, 2023 | Memory corruption in core due to buffer copy without check9ing the size of input while processing ioctl queries. |
| CVE-2022-22060 | HIGH | 7.5 | 0.4% | Jun 6, 2023 | Assertion occurs while processing Reconfiguration message due to improper validation |
| CVE-2022-48392 | HIGH | 7.8 | 0.1% | Jun 6, 2023 | In dialer service, there is a possible missing permission check. This could lead to local escalation of privilege with n... |
| CVE-2022-48390 | HIGH | 7.8 | 0.1% | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege wit... |
| CVE-2022-48188 | HIGH | 7.8 | 0.2% | Jun 5, 2023 | A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could al... |
| CVE-2022-48181 | HIGH | 7.8 | 0.2% | Jun 5, 2023 | An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker... |
| CVE-2022-4569 | HIGH | 7.8 | 0.2% | Jun 5, 2023 | A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow... |
| CVE-2022-47617 | HIGH | 7.2 | 0.5% | Jun 2, 2023 | Hitron CODA-5310 has hard-coded encryption/decryption keys in the program code. A remote attacker authenticated as an ad... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now