2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-36317MEDIUM6.5When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this co...
CVE-2022-36316MEDIUM6.1When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus le...
CVE-2022-36315MEDIUM4.3When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of prev...
CVE-2022-36314MEDIUM5.5When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to une...
CVE-2022-35646MEDIUM5.3 IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify ...
CVE-2022-34485CRITICAL9.8Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firef...
CVE-2022-34484HIGH8.8The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evid...
CVE-2022-34483HIGH8.8An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulti...
CVE-2022-34482HIGH8.8An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulti...
CVE-2022-34481HIGH8.8In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number...
CVE-2022-34480HIGH8.8Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer ...
CVE-2022-34479MEDIUM6.5A malicious website that could create a popup could have resized the popup to overlay the address bar with its own conte...
CVE-2022-34478MEDIUM6.5The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applica...
CVE-2022-34477HIGH7.5The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however ...
CVE-2022-34476CRITICAL9.8ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed...
CVE-2022-34475MEDIUM6.1SVG <code>&lt;use&gt;</code> tags that referenced a same-origin document could have resulted in script execution if atta...
CVE-2022-34474MEDIUM6.1Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect h...
CVE-2022-34473MEDIUM6.1The HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code>&lt;use&gt;</code> tags; however i...
CVE-2022-34472MEDIUM4.3If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, r...
CVE-2022-34471MEDIUM6.5When downloading an update for an addon, the downloaded addon update's version was not verified to match the version sel...
CVE-2022-34470CRITICAL9.8Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affec...
CVE-2022-34469HIGH8.1When a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to b...
CVE-2022-34468HIGH8.8An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This...
CVE-2022-31748CRITICAL9.8Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported m...
CVE-2022-31747CRITICAL9.8Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs presen...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now