2022 CVE Vulnerabilities

27,540 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-20305LOW3.3In ContentService, there is a possible disclosure of available account types due to a missing permission check. This cou...
CVE-2022-20304MEDIUM5.5In Content, there is a possible way to determinate the user's account due to side channel information disclosure. This c...
CVE-2022-20303MEDIUM5.5In ContentService, there is a possible way to determine if an account is on the device without GET_ACCOUNTS permission d...
CVE-2022-20302HIGH7.6In Settings, there is a possible way to bypass factory reset protections due to a sandbox escape. This could lead to loc...
CVE-2022-20301MEDIUM5.5In Content, there is a possible way to check if an account exists on the device due to a missing permission check. This ...
CVE-2022-20300MEDIUM5.5In Content, there is a possible way to check if the given account exists on the device due to a missing permission check...
CVE-2022-20299MEDIUM5.5In ContentService, there is a possible way to check if the given account exists on the device due to a missing permissio...
CVE-2022-20298MEDIUM5.5In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check...
CVE-2022-20297HIGH7.8In Settings, there is a possible way to bypass factory reset protections due to a logic error in the code. This could le...
CVE-2022-20296MEDIUM5.5In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check...
CVE-2022-20295MEDIUM5.5In ContentService, there is a possible way to check if an account exists on the device due to a missing permission check...
CVE-2022-20294MEDIUM5.5In Content, there is a possible way to learn about an account present on the device due to a missing permission check. T...
CVE-2022-20293MEDIUM5.5In LauncherApps, there is a possible way to determine whether an app is installed, without query permissions, due to sid...
CVE-2022-20292HIGH7.8In Settings, there is a possible way to bypass factory reset protections due to a logic error in the code. This could le...
CVE-2022-20291MEDIUM5.5In AppOpsService, there is a possible way to determine whether an app is installed, without query permissions, due to si...
CVE-2022-20290MEDIUM5.5In Midi, there is a possible way to learn about private midi devices due to a permissions bypass. This could lead to loc...
CVE-2022-20289MEDIUM5.5In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to...
CVE-2022-20288MEDIUM5.5In AppSearchManagerService, there is a possible way to determine whether an app is installed, without query permissions,...
CVE-2022-20287MEDIUM5.5In AppSearchManagerService, there is a possible way to determine whether an app is installed, without query permissions,...
CVE-2022-20286HIGH7.8In Connectivity, there is a possible bypass the restriction of starting activity from background due to a logic error in...
CVE-2022-20285MEDIUM5.5In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to s...
CVE-2022-20284MEDIUM5.5In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local inf...
CVE-2022-20283HIGH8.8In Bluetooth, there is a possible out of bounds write due to an integer overflow. This could lead to remote code executi...
CVE-2022-20282HIGH7.8In AppWidget, there is a possible way to start an activity from the background due to a missing permission check. This c...
CVE-2022-20281HIGH7.8In Core, there is a possible way to start an activity from the background due to a missing permission check. This could ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now