2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-3205MEDIUM6.1Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project na...
CVE-2022-3182HIGH7Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earl...
CVE-2022-38342MEDIUM6.5Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerab...
CVE-2022-37703LOW3.3In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vul...
CVE-2022-32555HIGH8.8Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenti...
CVE-2022-32244MEDIUM5.2Under certain conditions an attacker authenticated as a CMS administrator access the BOE Commentary database and retriev...
CVE-2022-2962HIGH7.8A DMA reentrancy issue was found in the Tulip device emulation in QEMU. When Tulip reads or writes to the rx/tx descript...
CVE-2022-20399MEDIUM5.5In the SEPolicy configuration of system apps, there is a possible access to the 'ip' utility due to an insecure default ...
CVE-2022-20398HIGH7.8In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure Wi-Fi due to a perm...
CVE-2022-20396MEDIUM5.5In SettingsActivity.java, there is a possible way to make a device discoverable over Bluetooth, without permission or us...
CVE-2022-20395HIGH7.8In checkAccess of MediaProvider.java, there is a possible file deletion due to a path traversal error. This could lead t...
CVE-2022-20393MEDIUM5.5In extract3GPPGlobalDescriptions of TextDescriptions.cpp, there is a possible out of bounds read due to an integer overf...
CVE-2022-20392HIGH7.8In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission wi...
CVE-2022-20391CRITICAL9.8Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257000
CVE-2022-20390CRITICAL9.8Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257002
CVE-2022-20389CRITICAL9.8Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257004
CVE-2022-20388CRITICAL9.8Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227323
CVE-2022-20387CRITICAL9.8Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227324
CVE-2022-20386CRITICAL9.8Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227328
CVE-2022-20385CRITICAL9.8a function called 'nla_parse', do not check the len of para, it will check nla_type (which can be controlled by userspac...
CVE-2022-40635HIGH7.2Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticat...
CVE-2022-40634HIGH7.2Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticat...
CVE-2022-39208HIGH7.5Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. All files in the /opt/onedev/sites/ directory ar...
CVE-2022-39207MEDIUM5.4Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. During CI/CD builds, it is possible to save buil...
CVE-2022-39206CRITICAL9.9Onedev is an open source, self-hosted Git Server with CI/CD and Kanban. When using Docker-based job executors, the Docke...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now