2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29439MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Image Slider by NextCode plugin <= 1.1.2 at WordPress allows deleting...
CVE-2022-29438MEDIUM4.8Authenticated (author or higher user role) Persistent Cross-Site Scripting (XSS) vulnerability in Image Slider by NextCo...
CVE-2022-29437HIGH8.8Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Image Slider by NextCode plugin <= 1.1.2 at WordPress.
CVE-2022-22444MEDIUM5.5IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user to exploit a vulnerability in the lpd daemon to cause a den...
CVE-2022-33140HIGH8.8The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not ne...
CVE-2022-29406MEDIUM5.4Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in DynamicWeb...
CVE-2022-27859MEDIUM5.4Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark d....
CVE-2022-20233MEDIUM6.7In param_find_digests_internal and related functions of the Titan-M source, there is a possible out of bounds write due ...
CVE-2022-20210CRITICAL9.8The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the mode...
CVE-2022-20209HIGH7.5In hme_add_new_node_to_a_sorted_array of hme_utils.c, there is a possible out of bounds read due to a heap buffer overfl...
CVE-2022-20208MEDIUM4.4In parseRecursively of cppbor_parse.cpp, there is a possible out of bounds read due to an incorrect bounds check. This c...
CVE-2022-20207HIGH7.8In static definitions of GattServiceConfig.java, there is a possible permission bypass due to an insecure default value....
CVE-2022-20206MEDIUM5.5In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead...
CVE-2022-20205MEDIUM5.5In isFileUri of FileUtil.java, there is a possible way to bypass the check for a file:// scheme due to improper input va...
CVE-2022-20204HIGH7.8In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug r...
CVE-2022-20202MEDIUM6.5In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42.c, there is a possible out of bounds read due to a h...
CVE-2022-20201MEDIUM6.7In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This c...
CVE-2022-20200MEDIUM5.5In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. Thi...
CVE-2022-20198MEDIUM4.4In llcp_dlc_proc_connect_pdu of llcp_dlc.cc, there is a possible out of bounds read due to a missing bounds check. This ...
CVE-2022-20197HIGH7.8In recycle of Parcel.java, there is a possible way to start foreground activity from background due to a permissions byp...
CVE-2022-20196MEDIUM5In gallery3d and photos, there is a possible permission bypass due to a confused deputy. This could lead to local inform...
CVE-2022-20195MEDIUM5In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This...
CVE-2022-20194HIGH7.8In onCreate of ChooseLockGeneric.java, there is a possible permission bypass. This could lead to local escalation of pri...
CVE-2022-20193HIGH7.3In getUniqueUsagesWithLabels of PermissionUsageHelper.java, there is a possible incorrect permission attribution due to ...
CVE-2022-20192HIGH7.8In grantEmbeddedWindowFocus of WindowManagerService.java, there is a possible way to change an input channel for embedde...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now