2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-45405MEDIUM6.5Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free a...
CVE-2022-45404MEDIUM6.5Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without...
CVE-2022-45403MEDIUM6.5Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for ...
CVE-2022-42929MEDIUM6.5If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may p...
CVE-2022-40961MEDIUM6.5During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially ex...
CVE-2022-40960MEDIUM6.5Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a ...
CVE-2022-40959MEDIUM6.5During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leak...
CVE-2022-40958MEDIUM6.5By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context c...
CVE-2022-40957MEDIUM6.5Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<b...
CVE-2022-40956MEDIUM6.1When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected elem...
CVE-2022-3266MEDIUM5.5An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerab...
CVE-2022-3034MEDIUM4.3When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to ...
CVE-2022-3032MEDIUM6.5When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute t...
CVE-2022-38475MEDIUM6.5An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was ze...
CVE-2022-38474MEDIUM4.3A website that had permission to access the microphone could record audio without the audio notification being shown. Th...
CVE-2022-38472MEDIUM6.5An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was...
CVE-2022-36318MEDIUM5.3When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability...
CVE-2022-36317MEDIUM6.5When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this co...
CVE-2022-36316MEDIUM6.1When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus le...
CVE-2022-36315MEDIUM4.3When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of prev...
CVE-2022-36314MEDIUM5.5When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to une...
CVE-2022-35646MEDIUM5.3 IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify ...
CVE-2022-34479MEDIUM6.5A malicious website that could create a popup could have resized the popup to overlay the address bar with its own conte...
CVE-2022-34478MEDIUM6.5The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applica...
CVE-2022-34475MEDIUM6.1SVG <code>&lt;use&gt;</code> tags that referenced a same-origin document could have resulted in script execution if atta...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now