2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-26383MEDIUM4.3When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This ...
CVE-2022-26382MEDIUM4.3While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fo...
CVE-2022-22762MEDIUM4.3Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed un...
CVE-2022-22760MEDIUM6.5When importing resources using Web Workers, error messages would distinguish the difference between <code>application/ja...
CVE-2022-22757MEDIUM6.5Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connec...
CVE-2022-22754MEDIUM6.5If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, ...
CVE-2022-22750MEDIUM6.5By generally accepting and passing resource handles across processes, a compromised content process might have confused ...
CVE-2022-22749MEDIUM4.3When scanning QR codes, Firefox for Android would have allowed navigation to some URLs that do not point to web content....
CVE-2022-22748MEDIUM6.5Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handlin...
CVE-2022-22747MEDIUM6.5After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have le...
CVE-2022-22746MEDIUM5.9A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window s...
CVE-2022-22745MEDIUM6.5Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerabi...
CVE-2022-22743MEDIUM4.3When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the...
CVE-2022-22742MEDIUM6.5When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potenti...
CVE-2022-22739MEDIUM6.5Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This ...
CVE-2022-1834MEDIUM6.5When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple...
CVE-2022-1520MEDIUM4.3When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both,...
CVE-2022-1197MEDIUM5.4When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the exis...
CVE-2022-1196MEDIUM6.5After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and pote...
CVE-2022-1097MEDIUM6.5<code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on differ...
CVE-2022-23541MEDIUM6.3jsonwebtoken is an implementation of JSON Web Tokens. Versions `<= 8.5.1` of `jsonwebtoken` library can be misconfigured...
CVE-2022-44510MEDIUM5.4Adobe Experience Manager version 6.5.14 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerabilit...
CVE-2022-41697MEDIUM5.3A user enumeration vulnerability exists in the login functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted ...
CVE-2022-41654MEDIUM4.3An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9...
CVE-2022-25948MEDIUM5.3The package liquidjs before 10.0.0 are vulnerable to Information Exposure when ownPropertyOnly parameter is set to False...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now