2022 CVE Vulnerabilities

27,526 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-2619MEDIUM4.3Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who c...
CVE-2022-2618MEDIUM6.5Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacke...
CVE-2022-2616MEDIUM6.5Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced...
CVE-2022-2615MEDIUM6.5Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cro...
CVE-2022-2612MEDIUM6.5Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who...
CVE-2022-2611MEDIUM4.3Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attac...
CVE-2022-2610MEDIUM6.5Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to...
CVE-2022-2605MEDIUM6.5Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap...
CVE-2022-35932MEDIUM5.3Nextcloud Talk is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.7, 13.0.7, and 14.0.3, passwo...
CVE-2022-35590MEDIUM4.8A cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "en...
CVE-2022-35589MEDIUM4.8A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publi...
CVE-2022-35587MEDIUM4.8A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publi...
CVE-2022-35585MEDIUM4.8A stored cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via ...
CVE-2022-37044MEDIUM6.1In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/search?action accepts parameters called extra, title, and onlo...
CVE-2022-37043MEDIUM5.7An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth,...
CVE-2022-28634MEDIUM6.7A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s)...
CVE-2022-28626MEDIUM6.7A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s)...
CVE-2022-20341MEDIUM5.5In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could ...
CVE-2022-20334MEDIUM6.5In Bluetooth, there are possible process crashes due to dereferencing a null pointer. This could lead to remote denial o...
CVE-2022-20333MEDIUM6.5In Bluetooth, there is a possible crash due to a missing null check. This could lead to remote denial of service with no...
CVE-2022-20332MEDIUM5.5In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to s...
CVE-2022-20326MEDIUM5.5In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to lo...
CVE-2022-20324MEDIUM5.5In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side c...
CVE-2022-20323MEDIUM5.5In PackageManager, there is a possible package installation disclosure due to a missing permission check. This could lea...
CVE-2022-20322MEDIUM5.5In PackageManager, there is a possible installed package disclosure due to a missing permission check. This could lead t...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now