2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29439 | MEDIUM | 4.3 | 0.4% | Jun 15, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in Image Slider by NextCode plugin <= 1.1.2 at WordPress allows deleting... |
| CVE-2022-29438 | MEDIUM | 4.8 | 0.5% | Jun 15, 2022 | Authenticated (author or higher user role) Persistent Cross-Site Scripting (XSS) vulnerability in Image Slider by NextCo... |
| CVE-2022-29437 | HIGH | 8.8 | 0.4% | Jun 15, 2022 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Image Slider by NextCode plugin <= 1.1.2 at WordPress. |
| CVE-2022-22444 | MEDIUM | 5.5 | 0.2% | Jun 15, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user to exploit a vulnerability in the lpd daemon to cause a den... |
| CVE-2022-33140 | HIGH | 8.8 | 3.6% | Jun 15, 2022 | The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not ne... |
| CVE-2022-29406 | MEDIUM | 5.4 | 0.6% | Jun 15, 2022 | Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in DynamicWeb... |
| CVE-2022-27859 | MEDIUM | 5.4 | 0.6% | Jun 15, 2022 | Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Nicdark d.... |
| CVE-2022-20233 | MEDIUM | 6.7 | 0.1% | Jun 15, 2022 | In param_find_digests_internal and related functions of the Titan-M source, there is a possible out of bounds write due ... |
| CVE-2022-20210 | CRITICAL | 9.8 | 3.4% | Jun 15, 2022 | The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the mode... |
| CVE-2022-20209 | HIGH | 7.5 | 0.7% | Jun 15, 2022 | In hme_add_new_node_to_a_sorted_array of hme_utils.c, there is a possible out of bounds read due to a heap buffer overfl... |
| CVE-2022-20208 | MEDIUM | 4.4 | 0.1% | Jun 15, 2022 | In parseRecursively of cppbor_parse.cpp, there is a possible out of bounds read due to an incorrect bounds check. This c... |
| CVE-2022-20207 | HIGH | 7.8 | 0.1% | Jun 15, 2022 | In static definitions of GattServiceConfig.java, there is a possible permission bypass due to an insecure default value.... |
| CVE-2022-20206 | MEDIUM | 5.5 | 0.1% | Jun 15, 2022 | In setPackageOrComponentEnabled of NotificationManagerService.java, there is a missing permission check. This could lead... |
| CVE-2022-20205 | MEDIUM | 5.5 | 0.1% | Jun 15, 2022 | In isFileUri of FileUtil.java, there is a possible way to bypass the check for a file:// scheme due to improper input va... |
| CVE-2022-20204 | HIGH | 7.8 | 0.1% | Jun 15, 2022 | In registerRemoteBugreportReceivers of DevicePolicyManagerService.java, there is a possible reporting of falsified bug r... |
| CVE-2022-20202 | MEDIUM | 6.5 | 0.6% | Jun 15, 2022 | In ih264_resi_trans_quant_4x4_sse42 of ih264_resi_trans_quant_sse42.c, there is a possible out of bounds read due to a h... |
| CVE-2022-20201 | MEDIUM | 6.7 | 0.1% | Jun 15, 2022 | In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This c... |
| CVE-2022-20200 | MEDIUM | 5.5 | 0.1% | Jun 15, 2022 | In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. Thi... |
| CVE-2022-20198 | MEDIUM | 4.4 | 0.1% | Jun 15, 2022 | In llcp_dlc_proc_connect_pdu of llcp_dlc.cc, there is a possible out of bounds read due to a missing bounds check. This ... |
| CVE-2022-20197 | HIGH | 7.8 | 0.1% | Jun 15, 2022 | In recycle of Parcel.java, there is a possible way to start foreground activity from background due to a permissions byp... |
| CVE-2022-20196 | MEDIUM | 5 | 0.1% | Jun 15, 2022 | In gallery3d and photos, there is a possible permission bypass due to a confused deputy. This could lead to local inform... |
| CVE-2022-20195 | MEDIUM | 5 | 0.2% | Jun 15, 2022 | In the keystore library, there is a possible prevention of access to system Settings due to unsafe deserialization. This... |
| CVE-2022-20194 | HIGH | 7.8 | 0.1% | Jun 15, 2022 | In onCreate of ChooseLockGeneric.java, there is a possible permission bypass. This could lead to local escalation of pri... |
| CVE-2022-20193 | HIGH | 7.3 | 0.1% | Jun 15, 2022 | In getUniqueUsagesWithLabels of PermissionUsageHelper.java, there is a possible incorrect permission attribution due to ... |
| CVE-2022-20192 | HIGH | 7.8 | 0.1% | Jun 15, 2022 | In grantEmbeddedWindowFocus of WindowManagerService.java, there is a possible way to change an input channel for embedde... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now