2022 CVE Vulnerabilities
27,553 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-29396 | CRITICAL | 9.8 | 1.5% | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the funct... |
| CVE-2022-29395 | CRITICAL | 9.8 | 1.5% | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the apcliKey parameter in the func... |
| CVE-2022-29394 | CRITICAL | 9.8 | 1.5% | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macAddress parameter in the fu... |
| CVE-2022-29393 | CRITICAL | 9.8 | 1.5% | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the funct... |
| CVE-2022-29392 | CRITICAL | 9.8 | 1.5% | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the funct... |
| CVE-2022-29391 | CRITICAL | 9.8 | 1.5% | May 10, 2022 | TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the funct... |
| CVE-2022-27167 | HIGH | 7.1 | 0.2% | May 10, 2022 | Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Un... |
| CVE-2022-20116 | HIGH | 7.8 | 0.1% | May 10, 2022 | In onEntryUpdated of OngoingCallController.kt, it is possible to launch non-exported activities due to intent redirectio... |
| CVE-2022-20115 | MEDIUM | 5.5 | 0.1% | May 10, 2022 | In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information wit... |
| CVE-2022-20114 | HIGH | 7.8 | 0.1% | May 10, 2022 | In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground s... |
| CVE-2022-20113 | HIGH | 7.8 | 0.2% | May 10, 2022 | In mPreference of DefaultUsbConfigurationPreferenceController.java, there is a possible way to enable file transfer mode... |
| CVE-2022-20112 | MEDIUM | 5.5 | 0.1% | May 10, 2022 | In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change priv... |
| CVE-2022-20011 | MEDIUM | 5.5 | 0.1% | May 10, 2022 | In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to mi... |
| CVE-2022-20010 | MEDIUM | 6.5 | 0.3% | May 10, 2022 | In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to an incorrect bounds check. This c... |
| CVE-2022-20009 | MEDIUM | 6.8 | 0.3% | May 10, 2022 | In various functions of the USB gadget subsystem, there is a possible out of bounds write due to a missing bounds check.... |
| CVE-2022-20008 | MEDIUM | 4.6 | 0.4% | May 10, 2022 | In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This co... |
| CVE-2022-20007 | HIGH | 7 | 0.2% | May 10, 2022 | In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app th... |
| CVE-2022-20006 | HIGH | 7 | 0.1% | May 10, 2022 | In several functions of KeyguardServiceWrapper.java and related files,, there is a possible way to briefly view what's u... |
| CVE-2022-20005 | HIGH | 7.8 | 0.2% | May 10, 2022 | In validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch between running code and... |
| CVE-2022-20004 | HIGH | 7.8 | 0.2% | May 10, 2022 | In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input valida... |
| CVE-2022-1567 | MEDIUM | 6.1 | 1.1% | May 10, 2022 | The WP-JS plugin for WordPress contains a script called wp-js.php with the function wp_js_admin, that accepts unvalidate... |
| CVE-2022-1505 | HIGH | 7.5 | 1.8% | May 10, 2022 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame... |
| CVE-2022-1476 | MEDIUM | 6.5 | 47.5% | May 10, 2022 | The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to... |
| CVE-2022-1463 | HIGH | 8.8 | 1.7% | May 10, 2022 | The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode ... |
| CVE-2022-1453 | HIGH | 7.5 | 6.9% | May 10, 2022 | The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now