2022 CVE Vulnerabilities

27,553 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-28784LOW3.3Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arb...
CVE-2022-28783HIGH7.1Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninst...
CVE-2022-28782MEDIUM4.6Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to ...
CVE-2022-28781MEDIUM6.7Improper input validation in Settings prior to SMR-May-2022 Release 1 allows attackers to launch arbitrary activity with...
CVE-2022-28780MEDIUM5.5Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access locati...
CVE-2022-27330MEDIUM5.4A cross-site scripting (XSS) vulnerability in /public/admin/index.php?add_product of E-Commerce Website v1.0 allows atta...
CVE-2022-27313HIGH7.5An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleti...
CVE-2022-20110HIGH7In ion, there is a possible use after free due to a race condition. This could lead to local escalation of privilege wit...
CVE-2022-20109HIGH7.8In ion, there is a possible use after free due to improper update of reference count. This could lead to local escalatio...
CVE-2022-20100MEDIUM4.4In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local in...
CVE-2022-20099HIGH7.8In aee daemon, there is a possible out of bounds write due to improper input validation. This could lead to local escala...
CVE-2022-20098MEDIUM4.4In aee daemon, there is a possible information disclosure due to a missing permission check. This could lead to local in...
CVE-2022-20097MEDIUM4.7In aee daemon, there is a possible information disclosure due to a race condition. This could lead to local information ...
CVE-2022-20096MEDIUM4.4In camera, there is a possible information disclosure due to uninitialized data. This could lead to local information di...
CVE-2022-20095MEDIUM6.7In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation...
CVE-2022-20094MEDIUM6.7In imgsensor, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalat...
CVE-2022-20093HIGH7.8In telephony, there is a possible way to disable receiving SMS messages due to a missing permission check. This could le...
CVE-2022-20092MEDIUM5.5In alac decoder, there is a possible out of bounds read due to a missing bounds check. This could lead to local informat...
CVE-2022-20091MEDIUM6.4In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privil...
CVE-2022-20090MEDIUM6.4In aee driver, there is a possible use after free due to a race condition. This could lead to local escalation of privil...
CVE-2022-20089MEDIUM6.7In aee driver, there is a possible memory corruption due to active debug code. This could lead to local escalation of pr...
CVE-2022-20088HIGH7.8In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local esc...
CVE-2022-20087MEDIUM6.7In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr...
CVE-2022-20085MEDIUM6.7In netdiag, there is a possible symbolic link following due to an improper link resolution. This could lead to local esc...
CVE-2022-20084HIGH7.8In telephony, there is a possible way to disable receiving emergency broadcasts due to a missing permission check. This ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now