2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26383 | MEDIUM | 4.3 | 0.7% | Dec 22, 2022 | When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This ... |
| CVE-2022-26382 | MEDIUM | 4.3 | 0.5% | Dec 22, 2022 | While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fo... |
| CVE-2022-22762 | MEDIUM | 4.3 | 0.4% | Dec 22, 2022 | Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed un... |
| CVE-2022-22760 | MEDIUM | 6.5 | 0.8% | Dec 22, 2022 | When importing resources using Web Workers, error messages would distinguish the difference between <code>application/ja... |
| CVE-2022-22757 | MEDIUM | 6.5 | 0.2% | Dec 22, 2022 | Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connec... |
| CVE-2022-22754 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, ... |
| CVE-2022-22750 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | By generally accepting and passing resource handles across processes, a compromised content process might have confused ... |
| CVE-2022-22749 | MEDIUM | 4.3 | 0.4% | Dec 22, 2022 | When scanning QR codes, Firefox for Android would have allowed navigation to some URLs that do not point to web content.... |
| CVE-2022-22748 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handlin... |
| CVE-2022-22747 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have le... |
| CVE-2022-22746 | MEDIUM | 5.9 | 0.6% | Dec 22, 2022 | A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window s... |
| CVE-2022-22745 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerabi... |
| CVE-2022-22743 | MEDIUM | 4.3 | 0.6% | Dec 22, 2022 | When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the... |
| CVE-2022-22742 | MEDIUM | 6.5 | 0.8% | Dec 22, 2022 | When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potenti... |
| CVE-2022-22739 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This ... |
| CVE-2022-1834 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple... |
| CVE-2022-1520 | MEDIUM | 4.3 | 0.3% | Dec 22, 2022 | When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both,... |
| CVE-2022-1197 | MEDIUM | 5.4 | 0.4% | Dec 22, 2022 | When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the exis... |
| CVE-2022-1196 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and pote... |
| CVE-2022-1097 | MEDIUM | 6.5 | 0.9% | Dec 22, 2022 | <code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on differ... |
| CVE-2022-23541 | MEDIUM | 6.3 | 0.8% | Dec 22, 2022 | jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured... |
| CVE-2022-44510 | MEDIUM | 5.4 | 0.5% | Dec 22, 2022 | Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2022-41697 | MEDIUM | 5.3 | 20.2% | Dec 22, 2022 | A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted ... |
| CVE-2022-41654 | MEDIUM | 4.3 | 18.9% | Dec 22, 2022 | An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9... |
| CVE-2022-25948 | MEDIUM | 5.3 | 0.8% | Dec 22, 2022 | The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now