2022 CVE Vulnerabilities
27,526 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-2619 | MEDIUM | 4.3 | 0.4% | Aug 12, 2022 | Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who c... |
| CVE-2022-2618 | MEDIUM | 6.5 | 0.6% | Aug 12, 2022 | Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacke... |
| CVE-2022-2616 | MEDIUM | 6.5 | 0.4% | Aug 12, 2022 | Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced... |
| CVE-2022-2615 | MEDIUM | 6.5 | 0.6% | Aug 12, 2022 | Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cro... |
| CVE-2022-2612 | MEDIUM | 6.5 | 0.6% | Aug 12, 2022 | Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who... |
| CVE-2022-2611 | MEDIUM | 4.3 | 0.5% | Aug 12, 2022 | Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attac... |
| CVE-2022-2610 | MEDIUM | 6.5 | 0.6% | Aug 12, 2022 | Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to... |
| CVE-2022-2605 | MEDIUM | 6.5 | 0.6% | Aug 12, 2022 | Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap... |
| CVE-2022-35932 | MEDIUM | 5.3 | 1.1% | Aug 12, 2022 | Nextcloud Talk is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.7, 13.0.7, and 14.0.3, passwo... |
| CVE-2022-35590 | MEDIUM | 4.8 | 0.6% | Aug 12, 2022 | A cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "en... |
| CVE-2022-35589 | MEDIUM | 4.8 | 0.6% | Aug 12, 2022 | A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publi... |
| CVE-2022-35587 | MEDIUM | 4.8 | 0.7% | Aug 12, 2022 | A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publi... |
| CVE-2022-35585 | MEDIUM | 4.8 | 0.7% | Aug 12, 2022 | A stored cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via ... |
| CVE-2022-37044 | MEDIUM | 6.1 | 0.4% | Aug 12, 2022 | In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/search?action accepts parameters called extra, title, and onlo... |
| CVE-2022-37043 | MEDIUM | 5.7 | 0.3% | Aug 12, 2022 | An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth,... |
| CVE-2022-28634 | MEDIUM | 6.7 | 0.2% | Aug 12, 2022 | A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s)... |
| CVE-2022-28626 | MEDIUM | 6.7 | 0.2% | Aug 12, 2022 | A local arbitrary code execution vulnerability was discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s)... |
| CVE-2022-20341 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could ... |
| CVE-2022-20334 | MEDIUM | 6.5 | 0.2% | Aug 12, 2022 | In Bluetooth, there are possible process crashes due to dereferencing a null pointer. This could lead to remote denial o... |
| CVE-2022-20333 | MEDIUM | 6.5 | 0.2% | Aug 12, 2022 | In Bluetooth, there is a possible crash due to a missing null check. This could lead to remote denial of service with no... |
| CVE-2022-20332 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to s... |
| CVE-2022-20326 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to lo... |
| CVE-2022-20324 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side c... |
| CVE-2022-20323 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In PackageManager, there is a possible package installation disclosure due to a missing permission check. This could lea... |
| CVE-2022-20322 | MEDIUM | 5.5 | 0.1% | Aug 12, 2022 | In PackageManager, there is a possible installed package disclosure due to a missing permission check. This could lead t... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now