2022 CVE Vulnerabilities
27,528 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-3821 | MEDIUM | 5.5 | 0.4% | Nov 8, 2022 | An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supp... |
| CVE-2022-39386 | HIGH | 7.5 | 0.7% | Nov 8, 2022 | @fastify/websocket provides WebSocket support for Fastify. Any application using @fastify/websocket could crash if a spe... |
| CVE-2022-37015 | CRITICAL | 9.8 | 0.7% | Nov 8, 2022 | Symantec Endpoint Detection and Response (SEDR) Appliance, prior to 4.7.0, may be susceptible to a privilege escalation ... |
| CVE-2022-34825 | CRITICAL | 9.8 | 1.2% | Nov 8, 2022 | Uncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earli... |
| CVE-2022-34824 | CRITICAL | 9.8 | 1.1% | Nov 8, 2022 | Weak File and Folder Permissions vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Win... |
| CVE-2022-34823 | CRITICAL | 9.8 | 1.2% | Nov 8, 2022 | Buffer overflow vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier,... |
| CVE-2022-34822 | CRITICAL | 9.8 | 1.4% | Nov 8, 2022 | Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, ... |
| CVE-2022-27516 | CRITICAL | 9.8 | 0.6% | Nov 8, 2022 | User login brute force protection functionality bypass |
| CVE-2022-27513 | CRITICAL | 9.6 | 0.3% | Nov 8, 2022 | Remote desktop takeover via phishing |
| CVE-2022-27510 | CRITICAL | 9.8 | 1.2% | Nov 8, 2022 | Unauthorized access to Gateway user capabilities |
| CVE-2022-20465 | MEDIUM | 4.6 | 0.9% | Nov 8, 2022 | In dismiss and related functions of KeyguardHostViewController.java and related files, there is a possible lockscreen by... |
| CVE-2022-20463 | — | — | — | Nov 8, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2022-20462 | HIGH | 7.8 | 0.1% | Nov 8, 2022 | In phNxpNciHal_write_unlocked of phNxpNciHal.cc, there is a possible out of bounds write due to a missing bounds check. ... |
| CVE-2022-20457 | MEDIUM | 5.5 | 0.1% | Nov 8, 2022 | In getMountModeInternal of StorageManagerService.java, there is a possible prevention of package installation due to imp... |
| CVE-2022-20454 | MEDIUM | 6.7 | 0.1% | Nov 8, 2022 | In fdt_next_tag of fdt.c, there is a possible out of bounds write due to an integer overflow. This could lead to local e... |
| CVE-2022-20453 | MEDIUM | 5.5 | 0.2% | Nov 8, 2022 | In update of MmsProvider.java, there is a possible constriction of directory permissions due to a path traversal error. ... |
| CVE-2022-20452 | HIGH | 7.8 | 0.4% | Nov 8, 2022 | In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused ... |
| CVE-2022-20451 | HIGH | 7.8 | 0.1% | Nov 8, 2022 | In onCallRedirectionComplete of CallsManager.java, there is a possible permissions bypass due to a missing permission ch... |
| CVE-2022-20450 | HIGH | 7.8 | 0.1% | Nov 8, 2022 | In restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way to bypass user consent due to a ... |
| CVE-2022-20448 | MEDIUM | 5.5 | 0.1% | Nov 8, 2022 | In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a p... |
| CVE-2022-20447 | MEDIUM | 6.5 | 0.3% | Nov 8, 2022 | In PAN_WriteBuf of pan_api.cc, there is a possible out of bounds read due to a use after free. This could lead to remote... |
| CVE-2022-20446 | LOW | 3.3 | 0.1% | Nov 8, 2022 | In AlwaysOnHotwordDetector of AlwaysOnHotwordDetector.java, there is a possible way to access the microphone from the ba... |
| CVE-2022-20445 | HIGH | 7.5 | 0.4% | Nov 8, 2022 | In process_service_search_rsp of sdp_discovery.cc, there is a possible out of bounds read due to improper input validati... |
| CVE-2022-20441 | HIGH | 7.8 | 0.1% | Nov 8, 2022 | In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the... |
| CVE-2022-20426 | MEDIUM | 5.5 | 0.1% | Nov 8, 2022 | In multiple functions of many files, there is a possible obstruction of the user's ability to select a phone account due... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now