2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-1488MEDIUM4.3Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4951.41 allowed an attacker who convinced...
CVE-2022-1487HIGH7.5Use after free in Ozone in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap co...
CVE-2022-1486HIGH8.8Type confusion in V8 in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to obtain potentially sensitive i...
CVE-2022-1485HIGH7.5Use after free in File System API in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially explo...
CVE-2022-1484HIGH8.8Heap buffer overflow in Web UI Settings in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially...
CVE-2022-1483HIGH8.8Heap buffer overflow in WebGPU in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who had compromised the...
CVE-2022-1482MEDIUM6.5Inappropriate implementation in WebGL in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially e...
CVE-2022-1481HIGH8.8Use after free in Sharing in Google Chrome on Mac prior to 101.0.4951.41 allowed a remote attacker who convinced a user ...
CVE-2022-1479HIGH8.8Use after free in ANGLE in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap co...
CVE-2022-1478HIGH8.8Use after free in SwiftShader in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit h...
CVE-2022-1477HIGH8.8Use after free in Vulkan in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap c...
CVE-2022-1364HIGH8.8Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit ...
CVE-2022-1671HIGH7.1A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw a...
CVE-2022-1651HIGH7.1A memory leak flaw was found in the Linux kernel in acrn_dev_ioctl in the drivers/virt/acrn/hsm.c function in how the AC...
CVE-2022-35639HIGH7.5IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cau...
CVE-2022-35286HIGH8.8IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker t...
CVE-2022-22412MEDIUM4.6IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with access to the local host (client machi...
CVE-2022-1648HIGH7.2Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a...
CVE-2022-36412CRITICAL9.8In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API r...
CVE-2022-36161CRITICAL9.8Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
CVE-2022-34991MEDIUM5.4Paymoney v3.3 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the first_name...
CVE-2022-34989CRITICAL9.8Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_passwo...
CVE-2022-34988MEDIUM5.4Inout Blockchain AltExchanger v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the compon...
CVE-2022-34067HIGH7.5Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter.
CVE-2022-33745HIGH8.8insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF ...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now