2022 CVE Vulnerabilities

27,538 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-2608HIGH8.8Use after free in Overview Mode in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convi...
CVE-2022-2607HIGH8.8Use after free in Tab Strip in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced...
CVE-2022-2606HIGH8.8Use after free in Managed devices API in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a ...
CVE-2022-2605MEDIUM6.5Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap...
CVE-2022-2604HIGH8.8Use after free in Safe Browsing in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit...
CVE-2022-2603HIGH8.8Use after free in Omnibox in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap ...
CVE-2022-2587CRITICAL9.8Out of bounds write in Chrome OS Audio Server in Google Chrome on Chrome OS prior to 102.0.5005.125 allowed a remote att...
CVE-2022-2797CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Student Information System. Affected by this vulnerab...
CVE-2022-35980HIGH7.5OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. Versions 2.0.0....
CVE-2022-35932MEDIUM5.3Nextcloud Talk is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.7, 13.0.7, and 14.0.3, passwo...
CVE-2022-35590MEDIUM4.8A cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via the "en...
CVE-2022-35589MEDIUM4.8A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publi...
CVE-2022-35587MEDIUM4.8A cross-site scripting (XSS) issue in the Fork version 5.9.3 allows remote attackers to inject JavaScript via the "publi...
CVE-2022-35585MEDIUM4.8A stored cross-site scripting (XSS) issue in the ForkCMS version 5.9.3 allows remote attackers to inject JavaScript via ...
CVE-2022-37423HIGH7.5Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling di...
CVE-2022-37044MEDIUM6.1In Zimbra Collaboration Suite (ZCS) 8.8.15, the URL at /h/search?action accepts parameters called extra, title, and onlo...
CVE-2022-37043MEDIUM5.7An issue was discovered in the webmail component in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. When using preauth,...
CVE-2022-37042CRITICAL9.8Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi...
CVE-2022-37041HIGH7.5An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0. T...
CVE-2022-35561HIGH7.5A stack overflow vulnerability exists in /goform/WifiMacFilterSet in Tenda W6 V1.0.0.9(4122) version, which can be explo...
CVE-2022-35560HIGH7.5A stack overflow vulnerability exists in /goform/wifiSSIDset in Tenda W6 V1.0.0.9(4122) version, which can be exploited ...
CVE-2022-35559CRITICAL9.8A stack overflow vulnerability exists in /goform/setAutoPing in Tenda W6 V1.0.0.9(4122), which allows an attacker to con...
CVE-2022-35558HIGH7.5A stack overflow vulnerability exists in /goform/WifiMacFilterGet in Tenda W6 V1.0.0.9(4122) version, which can be explo...
CVE-2022-35557HIGH7.5A stack overflow vulnerability exists in /goform/wifiSSIDget in Tenda W6 V1.0.0.9(4122) version, which can be exploited ...
CVE-2022-35555CRITICAL9.8A command injection vulnerability exists in /goform/exeCommand in Tenda W6 V1.0.0.9(4122), which allows attackers to con...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now