2022 CVE Vulnerabilities

27,541 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2719MEDIUM5.5In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/oper...
CVE-2022-2634CRITICAL9.8An attacker may be able to execute malicious actions due to the lack of device access protections and device permissions...
CVE-2022-2458HIGH8.2XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's process...
CVE-2022-2457CRITICAL9.8A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against...
CVE-2022-29804HIGH7.5Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and G...
CVE-2022-28881HIGH7.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the aerdl.dll component used in certai...
CVE-2022-28131HIGH7.5Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a pan...
CVE-2022-25793HIGH7.8A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through ...
CVE-2022-23238MEDIUM6.5Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux ...
CVE-2022-22983MEDIUM5.9VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious acto...
CVE-2022-20361CRITICAL9.8In btif_dm_auth_cmpl_evt of btif_dm.cc, there is a possible vulnerability in Cross-Transport Key Derivation due to Weakn...
CVE-2022-20360HIGH7.8In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escal...
CVE-2022-20359Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2022-20358LOW3.3In startSync of AbstractThreadedSyncAdapter.java, there is a possible way to access protected content of content provide...
CVE-2022-20357MEDIUM5.5In writeToParcel of SurfaceControl.cpp, there is a possible information disclosure due to uninitialized data. This could...
CVE-2022-20356HIGH7.8In shouldAllowFgsWhileInUsePermissionLocked of ActiveServices.java, there is a possible way to start foreground service ...
CVE-2022-20355MEDIUM5.5In get of PacProxyService.java, there is a possible system service crash due to improper input validation. This could le...
CVE-2022-20354HIGH7.8In onDefaultNetworkChanged of Vpn.java, there is a possible way to disable VPN due to a logic error in the code. This co...
CVE-2022-20353MEDIUM5.5In onSaveRingtone of DefaultRingtonePreference.java, there is a possible inappropriate file read due to improper input v...
CVE-2022-20352MEDIUM5.5In addProviderRequestListener of LocationManagerService.java, there is a possible way to learn which packages request lo...
CVE-2022-20350MEDIUM5.5In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notific...
CVE-2022-20349HIGH7.8In WifiScanningPreferenceController and BluetoothScanningPreferenceController, there is a possible admin restriction byp...
CVE-2022-20348HIGH7.8In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass du...
CVE-2022-20347HIGH8.8In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. Th...
CVE-2022-20346MEDIUM6.5In updateAudioTrackInfoFromESDS_MPEG4Audio of MPEG4Extractor.cpp, there is a possible out of bounds read due to an incor...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now