2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1489 | HIGH | 8.8 | 0.8% | Jul 26, 2022 | Out of bounds memory access in UI Shelf in Google Chrome on Chrome OS, Lacros prior to 101.0.4951.41 allowed a remote at... |
| CVE-2022-1487 | HIGH | 7.5 | 0.9% | Jul 26, 2022 | Use after free in Ozone in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap co... |
| CVE-2022-1486 | HIGH | 8.8 | 0.8% | Jul 26, 2022 | Type confusion in V8 in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to obtain potentially sensitive i... |
| CVE-2022-1485 | HIGH | 7.5 | 0.8% | Jul 26, 2022 | Use after free in File System API in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially explo... |
| CVE-2022-1484 | HIGH | 8.8 | 0.9% | Jul 26, 2022 | Heap buffer overflow in Web UI Settings in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially... |
| CVE-2022-1483 | HIGH | 8.8 | 1.0% | Jul 26, 2022 | Heap buffer overflow in WebGPU in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who had compromised the... |
| CVE-2022-1481 | HIGH | 8.8 | 0.9% | Jul 26, 2022 | Use after free in Sharing in Google Chrome on Mac prior to 101.0.4951.41 allowed a remote attacker who convinced a user ... |
| CVE-2022-1479 | HIGH | 8.8 | 0.8% | Jul 26, 2022 | Use after free in ANGLE in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap co... |
| CVE-2022-1478 | HIGH | 8.8 | 0.8% | Jul 26, 2022 | Use after free in SwiftShader in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit h... |
| CVE-2022-1477 | HIGH | 8.8 | 0.9% | Jul 26, 2022 | Use after free in Vulkan in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap c... |
| CVE-2022-1364 | HIGH | 8.8 | 13.7% | Jul 26, 2022 | Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit ... |
| CVE-2022-1671 | HIGH | 7.1 | 0.3% | Jul 26, 2022 | A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw a... |
| CVE-2022-1651 | HIGH | 7.1 | 0.2% | Jul 26, 2022 | A memory leak flaw was found in the Linux kernel in acrn_dev_ioctl in the drivers/virt/acrn/hsm.c function in how the AC... |
| CVE-2022-35639 | HIGH | 7.5 | 0.8% | Jul 26, 2022 | IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cau... |
| CVE-2022-35286 | HIGH | 8.8 | 0.3% | Jul 26, 2022 | IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker t... |
| CVE-2022-1648 | HIGH | 7.2 | 1.0% | Jul 26, 2022 | Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a... |
| CVE-2022-34067 | HIGH | 7.5 | 0.8% | Jul 26, 2022 | Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter. |
| CVE-2022-33745 | HIGH | 8.8 | 0.3% | Jul 26, 2022 | insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF ... |
| CVE-2022-31879 | HIGH | 8.8 | 1.1% | Jul 26, 2022 | Online Fire Reporting System 1.0 is vulnerable to SQL Injection via the date parameter. |
| CVE-2022-2225 | HIGH | 7.8 | 0.2% | Jul 26, 2022 | By using warp-cli subcommands (disable-ethernet, disable-wifi), it was possible for a user without admin privileges to b... |
| CVE-2022-33977 | HIGH | 7.5 | 1.4% | Jul 26, 2022 | untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restr... |
| CVE-2022-31471 | HIGH | 7.5 | 1.3% | Jul 26, 2022 | untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restr... |
| CVE-2022-1042 | HIGH | 8.8 | 0.8% | Jul 26, 2022 | In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning. |
| CVE-2022-1041 | HIGH | 8.8 | 0.8% | Jul 26, 2022 | In Zephyr bluetooth mesh core stack, an out-of-bound write vulnerability can be triggered during provisioning. |
| CVE-2022-22686 | HIGH | 8 | 0.3% | Jul 26, 2022 | Cross-Site Request Forgery (CSRF) vulnerability in webapi component in Synology Calendar before 2.3.4-0631 allows remote... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now