2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-27470HIGH7.8SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). T...
CVE-2022-27431CRITICAL9.8Wuzhicms v4.1.0 was discovered to contain a SQL injection vulnerability via the groupid parameter at /coreframe/app/memb...
CVE-2022-27420CRITICAL9.8Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact paramete...
CVE-2022-24901HIGH7.5Improper validation of the Apple certificate URL in the Apple Game Center authentication adapter allows attackers to byp...
CVE-2022-27413CRITICAL9.8Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in a...
CVE-2022-21743HIGH7.8In ion, there is a possible use after free due to an integer overflow. This could lead to local escalation of privilege ...
CVE-2022-20111HIGH8.4In ion, there is a possible use after free due to incorrect error handling. This could lead to local escalation of privi...
CVE-2022-20108MEDIUM6.7In voice service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local...
CVE-2022-20107MEDIUM4.4In subtitle service, there is a possible application crash due to an integer overflow. This could lead to local denial o...
CVE-2022-20106MEDIUM6.7In MM service, there is a possible out of bounds write due to a heap-based buffer overflow. This could lead to local esc...
CVE-2022-20105MEDIUM6.7In MM service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local es...
CVE-2022-20104MEDIUM5.5In aee daemon, there is a possible information disclosure due to improper access control. This could lead to local infor...
CVE-2022-20103MEDIUM4.4In aee daemon, there is a possible information disclosure due to symbolic link following. This could lead to local infor...
CVE-2022-20102MEDIUM4.4In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local in...
CVE-2022-20101MEDIUM5.5In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information ...
CVE-2022-1548HIGH8.8Mattermost Playbooks plugin 1.25 and earlier fails to properly restrict user-level permissions, which allows playbook me...
CVE-2022-28793MEDIUM4.4Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to...
CVE-2022-28792HIGH7.8DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary...
CVE-2022-28791MEDIUM5.5Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to ove...
CVE-2022-28790LOW3.3Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The pat...
CVE-2022-28789MEDIUM5.5Unprotected activities in Voice Note prior to version 21.3.51.11 allows attackers to record voice without user interacti...
CVE-2022-28788MEDIUM5.5Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leadi...
CVE-2022-28787MEDIUM5.5Improper buffer size check logic in wmfextractor library prior to SMR May-2022 Release 1 allows out of bounds read leadi...
CVE-2022-28786MEDIUM5.5Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leadi...
CVE-2022-28785MEDIUM5.5Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leadi...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now