2022 CVE Vulnerabilities

27,528 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-44550HIGH7.5The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vuln...
CVE-2022-44549HIGH7.5The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause thi...
CVE-2022-44548MEDIUM4.3There is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of thi...
CVE-2022-44547HIGH7.5The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display...
CVE-2022-44546HIGH7.5The kernel module has the vulnerability that the mapping is not cleared after the memory is automatically released. Succ...
CVE-2022-43310HIGH7.8An Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate...
CVE-2022-43058CRITICAL9.8Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id paramete...
CVE-2022-43031HIGH8.8DedeCMS v6.1.9 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add A...
CVE-2022-31689CRITICAL9.8VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a va...
CVE-2022-31688MEDIUM6.1VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to imprope...
CVE-2022-31687CRITICAL9.8VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with networ...
CVE-2022-31686CRITICAL9.8VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with...
CVE-2022-31685CRITICAL9.8VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with netwo...
CVE-2022-29836MEDIUM4.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was discovered via an HTTP ...
CVE-2022-27674HIGH7.5Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks pote...
CVE-2022-27673HIGH7.5Insufficient access controls in the AMD Link Android app may potentially result in information disclosure.
CVE-2022-23831HIGH7.5Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading...
CVE-2022-23824MEDIUM5.5IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential in...
CVE-2022-42966HIGH7.5An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker ...
CVE-2022-42965HIGH7.5An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI pack...
CVE-2022-42964HIGH7.5An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the pymatgen PyPI package, when an attac...
CVE-2022-3450HIGH8.8Use after free in Peer Connection in Google Chrome prior to 106.0.5249.119 allowed a remote attacker to potentially expl...
CVE-2022-3449HIGH8.8Use after free in Safe Browsing in Google Chrome prior to 106.0.5249.119 allowed an attacker who convinced a user to ins...
CVE-2022-3448HIGH8.8Use after free in Permissions API in Google Chrome prior to 106.0.5249.119 allowed a remote attacker who convinced a use...
CVE-2022-3447MEDIUM4.3Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 106.0.5249.119 allowed a remote attacke...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now