2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-32114 | HIGH | 8.8 | 1.6% | Jul 13, 2022 | An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XS... |
| CVE-2022-31145 | MEDIUM | 6.5 | 0.8% | Jul 13, 2022 | FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. In ve... |
| CVE-2022-32308 | MEDIUM | 6.1 | 0.5% | Jul 13, 2022 | Cross Site Scripting (XSS) vulnerability in uBlock Origin extension before 1.41.1 allows remote attackers to run arbitra... |
| CVE-2022-2380 | MEDIUM | 5.5 | 0.2% | Jul 13, 2022 | The Linux kernel was found vulnerable out of bounds memory access in the drivers/video/fbdev/sm712fb.c:smtcfb_read() fun... |
| CVE-2022-22982 | HIGH | 7.5 | 0.8% | Jul 13, 2022 | The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to... |
| CVE-2022-20238 | CRITICAL | 9.8 | 0.5% | Jul 13, 2022 | 'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->v... |
| CVE-2022-20236 | HIGH | 7.5 | 0.4% | Jul 13, 2022 | A drm driver have oob problem, could cause the system crash or EOPProduct: AndroidVersions: Android SoCAndroid ID: A-233... |
| CVE-2022-20234 | HIGH | 7.5 | 0.3% | Jul 13, 2022 | In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessConfirmationActivity, ... |
| CVE-2022-20230 | MEDIUM | 5.5 | 0.1% | Jul 13, 2022 | In choosePrivateKeyAlias of KeyChain.java, there is a possible access to the user's certificate due to improper input va... |
| CVE-2022-20229 | CRITICAL | 9.8 | 2.1% | Jul 13, 2022 | In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing ... |
| CVE-2022-20228 | MEDIUM | 6.5 | 0.5% | Jul 13, 2022 | In various functions of C2DmaBufAllocator.cpp, there is a possible memory corruption due to a use after free. This could... |
| CVE-2022-20227 | MEDIUM | 5.5 | 0.1% | Jul 13, 2022 | In USB driver, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informatio... |
| CVE-2022-20226 | LOW | 3.9 | 0.1% | Jul 13, 2022 | In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. Th... |
| CVE-2022-20225 | MEDIUM | 5.5 | 0.1% | Jul 13, 2022 | In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a m... |
| CVE-2022-20224 | HIGH | 7.5 | 1.0% | Jul 13, 2022 | In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This co... |
| CVE-2022-20223 | HIGH | 7.8 | 0.2% | Jul 13, 2022 | In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start a phone call withou... |
| CVE-2022-20222 | CRITICAL | 9.8 | 0.9% | Jul 13, 2022 | In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check. This could lead... |
| CVE-2022-20221 | MEDIUM | 6.5 | 0.2% | Jul 13, 2022 | In avrc_ctrl_pars_vendor_cmd of avrc_pars_ct.cc, there is a possible out of bounds read due to improper input validation... |
| CVE-2022-20220 | HIGH | 7.8 | 0.2% | Jul 13, 2022 | In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lea... |
| CVE-2022-20219 | MEDIUM | 5.5 | 0.1% | Jul 13, 2022 | In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's... |
| CVE-2022-20218 | HIGH | 7.8 | 0.1% | Jul 13, 2022 | In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic err... |
| CVE-2022-20217 | MEDIUM | 6.5 | 0.3% | Jul 13, 2022 | There is a unauthorized broadcast in the SprdContactsProvider. A third-party app could use this issue to delete Fdn cont... |
| CVE-2022-20216 | CRITICAL | 9.8 | 0.5% | Jul 13, 2022 | android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com.... |
| CVE-2022-20212 | HIGH | 7.8 | 0.1% | Jul 13, 2022 | In wifi.RequestToggleWifiActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. Th... |
| CVE-2022-28888 | CRITICAL | 9.8 | 3.6% | Jul 13, 2022 | Spryker Commerce OS 1.4.2 allows Remote Command Execution. |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now