2022 CVE Vulnerabilities
27,527 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-31746 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. ... |
| CVE-2022-31745 | MEDIUM | 4.3 | 0.3% | Dec 22, 2022 | If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnera... |
| CVE-2022-31744 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so by... |
| CVE-2022-31743 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. Th... |
| CVE-2022-31742 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the ... |
| CVE-2022-31741 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further ... |
| CVE-2022-31740 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a... |
| CVE-2022-31739 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly bein... |
| CVE-2022-31738 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting... |
| CVE-2022-31737 | CRITICAL | 9.8 | 0.8% | Dec 22, 2022 | A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially ex... |
| CVE-2022-31736 | CRITICAL | 9.8 | 1.1% | Dec 22, 2022 | A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerabi... |
| CVE-2022-2505 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs s... |
| CVE-2022-2226 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | An OpenPGP digital signature includes information about the date when the signature was created. When displaying an emai... |
| CVE-2022-2200 | HIGH | 8.8 | 23.9% | Dec 22, 2022 | If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScri... |
| CVE-2022-29918 | HIGH | 8.8 | 0.5% | Dec 22, 2022 | Mozilla developers Gabriele Svelto, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Fi... |
| CVE-2022-29917 | CRITICAL | 9.8 | 1.0% | Dec 22, 2022 | Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bug... |
| CVE-2022-29916 | MEDIUM | 6.5 | 0.7% | Dec 22, 2022 | Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. Thi... |
| CVE-2022-29915 | MEDIUM | 4.3 | 0.3% | Dec 22, 2022 | The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This ... |
| CVE-2022-29914 | MEDIUM | 6.5 | 0.6% | Dec 22, 2022 | When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have e... |
| CVE-2022-29913 | MEDIUM | 6.5 | 0.4% | Dec 22, 2022 | The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions... |
| CVE-2022-29912 | MEDIUM | 6.1 | 0.6% | Dec 22, 2022 | Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affec... |
| CVE-2022-29911 | MEDIUM | 6.1 | 0.6% | Dec 22, 2022 | An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could ... |
| CVE-2022-29910 | MEDIUM | 6.1 | 0.4% | Dec 22, 2022 | When closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note... |
| CVE-2022-29909 | HIGH | 8.8 | 0.8% | Dec 22, 2022 | Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origi... |
| CVE-2022-28289 | HIGH | 8.8 | 0.7% | Dec 22, 2022 | Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team r... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now