2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-4918HIGH8.8Use after free in UI in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform arbitrary read/write v...
CVE-2022-4917MEDIUM4.3Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to o...
CVE-2022-4916HIGH8.8Use after free in Media in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform arbitrary read/writ...
CVE-2022-4915MEDIUM6.5Inappropriate implementation in URL Formatting in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to per...
CVE-2022-4914HIGH8.8Heap buffer overflow in PrintPreview in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to...
CVE-2022-4913MEDIUM6.5Inappropriate implementation in Extensions in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had com...
CVE-2022-4912HIGH8.8Type Confusion in MathML in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap c...
CVE-2022-4911MEDIUM6.5Insufficient data validation in DevTools in Google Chrome prior to 106.0.5249.62 allowed a remote attacker to bypass con...
CVE-2022-4910MEDIUM5.4Inappropriate implementation in Autofill in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to bypass nav...
CVE-2022-4909MEDIUM6.3Inappropriate implementation in XML in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to potentially per...
CVE-2022-4908MEDIUM4.3Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 107.0.5304.62 allowed a remote attacker to leak...
CVE-2022-4907HIGH8.8Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to execute arbitrary code ...
CVE-2022-4906HIGH8.8Inappropriate implementation in Blink in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to perform arbit...
CVE-2022-31454MEDIUM6.1Yii 2 v2.0.45 was discovered to contain a cross-site scripting (XSS) vulnerability via the endpoint /books. NOTE: this i...
CVE-2022-43703HIGH7.8An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under...
CVE-2022-43702HIGH7.8When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can mod...
CVE-2022-43701HIGH7.8When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in...
CVE-2022-31200MEDIUM6.1Atmail 5.62 allows XSS via the mail/parse.php?file=html/$this-%3ELanguage/help/filexp.html&FirstLoad=1&HelpFile=file.htm...
CVE-2022-31455MEDIUM6.1* A cross-site scripting (XSS) vulnerability in Truedesk v1.2.2 allows attackers to execute arbitrary web scripts or HTM...
CVE-2022-31456MEDIUM6.1A cross-site scripting (XSS) vulnerability in Truedesk v1.2.2 allows attackers to execute arbitrary web scripts or HTML ...
CVE-2022-43713HIGH7.5Interactive Forms (IAF) in GX Software XperienCentral versions 10.33.1 until 10.35.0 was vulnerable to invalid data inpu...
CVE-2022-43712MEDIUM6.5POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are n...
CVE-2022-43711MEDIUM6.1Interactive Forms (IAF) in GX Software XperienCentral versions 10.29.1 until 10.33.0 was vulnerable to cross site script...
CVE-2022-43710HIGH8.8Interactive Forms (IAF) in GX Software XperienCentral versions 10.31.0 until 10.33.0 was vulnerable to cross site reques...
CVE-2022-4608HIGH7.5A vulnerability exists in HCI IEC 60870-5-104 function included in certain versions of the RTU500 series product. The vu...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now