2022 CVE Vulnerabilities
27,525 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-4900 | MEDIUM | 5.5 | 0.4% | Nov 2, 2023 | A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to... |
| CVE-2022-48461 | MEDIUM | 4.4 | 0.1% | Nov 1, 2023 | In sensor driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial... |
| CVE-2022-48460 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In setting service, there is a possible undefined behavior due to incorrect error handling. This could lead to local den... |
| CVE-2022-48459 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of se... |
| CVE-2022-48458 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of se... |
| CVE-2022-48457 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In TeleService, there is a possible system crash due to improper input validation. This could lead to local denial of se... |
| CVE-2022-48456 | MEDIUM | 4.4 | 0.1% | Nov 1, 2023 | In camera driver, there is a possible out of bounds write due to a incorrect bounds check. This could lead to local deni... |
| CVE-2022-48455 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial ... |
| CVE-2022-48454 | MEDIUM | 5.5 | 0.1% | Nov 1, 2023 | In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial ... |
| CVE-2022-39172 | MEDIUM | 5.4 | 0.6% | Oct 30, 2023 | A stored XSS in the process overview (bersicht zugewiesener Vorgaenge) in mbsupport openVIVA c2 20220101 allows a remote... |
| CVE-2022-20264 | MEDIUM | 5.5 | 0.1% | Oct 30, 2023 | In Usage Stats Service, there is a possible way to determine whether an app is installed, without query permissions due ... |
| CVE-2022-4575 | MEDIUM | 6.7 | 0.2% | Oct 30, 2023 | A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models cou... |
| CVE-2022-4574 | MEDIUM | 6.7 | 0.2% | Oct 30, 2023 | An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local ac... |
| CVE-2022-4573 | MEDIUM | 6.7 | 0.2% | Oct 30, 2023 | An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access a... |
| CVE-2022-48189 | MEDIUM | 6.7 | 0.2% | Oct 30, 2023 | An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local acce... |
| CVE-2022-34834 | MEDIUM | 4.8 | 0.4% | Oct 27, 2023 | An issue was discovered in VERMEG AgileReporter 21.3. Attackers can gain privileges via an XSS payload in an Add Comment... |
| CVE-2022-34833 | MEDIUM | 5.4 | 0.4% | Oct 27, 2023 | An issue was discovered in VERMEG AgileReporter 21.3. An admin can enter an XSS payload in the Analysis component. |
| CVE-2022-34832 | MEDIUM | 6.5 | 0.7% | Oct 27, 2023 | An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component. |
| CVE-2022-3700 | MEDIUM | 6.3 | 0.1% | Oct 27, 2023 | A Time of Check Time of Use (TOCTOU) vulnerability was reported in the Lenovo Vantage SystemUpdate Plugin version 2.0.0.... |
| CVE-2022-3681 | MEDIUM | 6.5 | 0.2% | Oct 27, 2023 | A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range o... |
| CVE-2022-3429 | MEDIUM | 6.5 | 0.5% | Oct 27, 2023 | A denial-of-service vulnerability was found in the firmware used in Lenovo printers, where users send illegal or malform... |
| CVE-2022-34887 | MEDIUM | 5.4 | 0.3% | Oct 27, 2023 | Standard users can directly operate and set printer configuration information , such as IP, in some Lenovo Printers with... |
| CVE-2022-4886 | MEDIUM | 6.5 | 1.6% | Oct 25, 2023 | Ingress-nginx `path` sanitization can be bypassed with `log_format` directive. |
| CVE-2022-3698 | MEDIUM | 4.4 | 0.2% | Oct 25, 2023 | A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Len... |
| CVE-2022-38485 | MEDIUM | 6.5 | 3.1% | Oct 25, 2023 | A directory traversal vulnerability exists in the AgeVolt Portal prior to version 0.1 that leads to Information Disclosu... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now