2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-32114HIGH8.8An unrestricted file upload vulnerability in the Add New Assets function of Strapi 4.1.12 allows attackers to conduct XS...
CVE-2022-31145MEDIUM6.5FlyteAdmin is the control plane for Flyte responsible for managing entities and administering workflow executions. In ve...
CVE-2022-32308MEDIUM6.1Cross Site Scripting (XSS) vulnerability in uBlock Origin extension before 1.41.1 allows remote attackers to run arbitra...
CVE-2022-2380MEDIUM5.5The Linux kernel was found vulnerable out of bounds memory access in the drivers/video/fbdev/sm712fb.c:smtcfb_read() fun...
CVE-2022-22982HIGH7.5The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to...
CVE-2022-20238CRITICAL9.8'remap_pfn_range' here may map out of size kernel memory (for example, may map the kernel area), and because the 'vma->v...
CVE-2022-20236HIGH7.5A drm driver have oob problem, could cause the system crash or EOPProduct: AndroidVersions: Android SoCAndroid ID: A-233...
CVE-2022-20234HIGH7.5In Car Settings app, the NotificationAccessConfirmationActivity is exported. In NotificationAccessConfirmationActivity, ...
CVE-2022-20230MEDIUM5.5In choosePrivateKeyAlias of KeyChain.java, there is a possible access to the user's certificate due to improper input va...
CVE-2022-20229CRITICAL9.8In bta_hf_client_handle_cind_list_item of bta_hf_client_at.cc, there is a possible out of bounds write due to a missing ...
CVE-2022-20228MEDIUM6.5In various functions of C2DmaBufAllocator.cpp, there is a possible memory corruption due to a use after free. This could...
CVE-2022-20227MEDIUM5.5In USB driver, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informatio...
CVE-2022-20226LOW3.9In finishDrawingWindow of WindowManagerService.java, there is a possible tapjacking due to improper input validation. Th...
CVE-2022-20225MEDIUM5.5In getSubscriptionProperty of SubscriptionController.java, there is a possible read of a sensitive identifier due to a m...
CVE-2022-20224HIGH7.5In AT_SKIP_REST of bta_hf_client_at.cc, there is a possible out of bounds read due to an incorrect bounds check. This co...
CVE-2022-20223HIGH7.8In assertSafeToStartCustomActivity of AppRestrictionsFragment.java, there is a possible way to start a phone call withou...
CVE-2022-20222CRITICAL9.8In read_attr_value of gatt_db.cc, there is a possible out of bounds write due to a missing bounds check. This could lead...
CVE-2022-20221MEDIUM6.5In avrc_ctrl_pars_vendor_cmd of avrc_pars_ct.cc, there is a possible out of bounds read due to improper input validation...
CVE-2022-20220HIGH7.8In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lea...
CVE-2022-20219MEDIUM5.5In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's...
CVE-2022-20218HIGH7.8In PermissionController, there is a possible way to get and retain permissions without user's consent due to a logic err...
CVE-2022-20217MEDIUM6.5There is a unauthorized broadcast in the SprdContactsProvider. A third-party app could use this issue to delete Fdn cont...
CVE-2022-20216CRITICAL9.8android exported is used to set third-party app access permissions, and the default value of intent-filter is true. com....
CVE-2022-20212HIGH7.8In wifi.RequestToggleWifiActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. Th...
CVE-2022-28888CRITICAL9.8Spryker Commerce OS 1.4.2 allows Remote Command Execution.

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now