2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-29396CRITICAL9.8TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the funct...
CVE-2022-29395CRITICAL9.8TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the apcliKey parameter in the func...
CVE-2022-29394CRITICAL9.8TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macAddress parameter in the fu...
CVE-2022-29393CRITICAL9.8TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the funct...
CVE-2022-29392CRITICAL9.8TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the funct...
CVE-2022-29391CRITICAL9.8TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the funct...
CVE-2022-27167HIGH7.1Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Un...
CVE-2022-20116HIGH7.8In onEntryUpdated of OngoingCallController.kt, it is possible to launch non-exported activities due to intent redirectio...
CVE-2022-20115MEDIUM5.5In broadcastServiceStateChanged of TelephonyRegistry.java, there is a possible way to learn base station information wit...
CVE-2022-20114HIGH7.8In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground s...
CVE-2022-20113HIGH7.8In mPreference of DefaultUsbConfigurationPreferenceController.java, there is a possible way to enable file transfer mode...
CVE-2022-20112MEDIUM5.5In getAvailabilityStatus of PrivateDnsPreferenceController.java, there is a possible way for a guest user to change priv...
CVE-2022-20011MEDIUM5.5In getArray of NotificationManagerService.java , there is a possible leak of one user notifications to another due to mi...
CVE-2022-20010MEDIUM6.5In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to an incorrect bounds check. This c...
CVE-2022-20009MEDIUM6.8In various functions of the USB gadget subsystem, there is a possible out of bounds write due to a missing bounds check....
CVE-2022-20008MEDIUM4.6In mmc_blk_read_single of block.c, there is a possible way to read kernel heap memory due to uninitialized data. This co...
CVE-2022-20007HIGH7In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app th...
CVE-2022-20006HIGH7In several functions of KeyguardServiceWrapper.java and related files,, there is a possible way to briefly view what's u...
CVE-2022-20005HIGH7.8In validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch between running code and...
CVE-2022-20004HIGH7.8In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input valida...
CVE-2022-1567MEDIUM6.1The WP-JS plugin for WordPress contains a script called wp-js.php with the function wp_js_admin, that accepts unvalidate...
CVE-2022-1505HIGH7.5The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame...
CVE-2022-1476MEDIUM6.5The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to...
CVE-2022-1463HIGH8.8The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode ...
CVE-2022-1453HIGH7.5The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parame...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now