2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1488 | MEDIUM | 4.3 | 0.5% | Jul 26, 2022 | Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4951.41 allowed an attacker who convinced... |
| CVE-2022-1487 | HIGH | 7.5 | 0.9% | Jul 26, 2022 | Use after free in Ozone in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap co... |
| CVE-2022-1486 | HIGH | 8.8 | 0.8% | Jul 26, 2022 | Type confusion in V8 in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to obtain potentially sensitive i... |
| CVE-2022-1485 | HIGH | 7.5 | 0.8% | Jul 26, 2022 | Use after free in File System API in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially explo... |
| CVE-2022-1484 | HIGH | 8.8 | 0.9% | Jul 26, 2022 | Heap buffer overflow in Web UI Settings in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially... |
| CVE-2022-1483 | HIGH | 8.8 | 1.0% | Jul 26, 2022 | Heap buffer overflow in WebGPU in Google Chrome prior to 101.0.4951.41 allowed a remote attacker who had compromised the... |
| CVE-2022-1482 | MEDIUM | 6.5 | 0.7% | Jul 26, 2022 | Inappropriate implementation in WebGL in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially e... |
| CVE-2022-1481 | HIGH | 8.8 | 0.9% | Jul 26, 2022 | Use after free in Sharing in Google Chrome on Mac prior to 101.0.4951.41 allowed a remote attacker who convinced a user ... |
| CVE-2022-1479 | HIGH | 8.8 | 0.8% | Jul 26, 2022 | Use after free in ANGLE in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap co... |
| CVE-2022-1478 | HIGH | 8.8 | 0.8% | Jul 26, 2022 | Use after free in SwiftShader in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit h... |
| CVE-2022-1477 | HIGH | 8.8 | 0.9% | Jul 26, 2022 | Use after free in Vulkan in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap c... |
| CVE-2022-1364 | HIGH | 8.8 | 13.7% | Jul 26, 2022 | Type confusion in V8 Turbofan in Google Chrome prior to 100.0.4896.127 allowed a remote attacker to potentially exploit ... |
| CVE-2022-1671 | HIGH | 7.1 | 0.3% | Jul 26, 2022 | A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw a... |
| CVE-2022-1651 | HIGH | 7.1 | 0.2% | Jul 26, 2022 | A memory leak flaw was found in the Linux kernel in acrn_dev_ioctl in the drivers/virt/acrn/hsm.c function in how the AC... |
| CVE-2022-35639 | HIGH | 7.5 | 0.8% | Jul 26, 2022 | IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cau... |
| CVE-2022-35286 | HIGH | 8.8 | 0.3% | Jul 26, 2022 | IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker t... |
| CVE-2022-22412 | MEDIUM | 4.6 | 0.3% | Jul 26, 2022 | IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user with access to the local host (client machi... |
| CVE-2022-1648 | HIGH | 7.2 | 1.0% | Jul 26, 2022 | Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a... |
| CVE-2022-36412 | CRITICAL | 9.8 | 5.7% | Jul 26, 2022 | In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API r... |
| CVE-2022-36161 | CRITICAL | 9.8 | 1.0% | Jul 26, 2022 | Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. |
| CVE-2022-34991 | MEDIUM | 5.4 | 0.4% | Jul 26, 2022 | Paymoney v3.3 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities via the first_name... |
| CVE-2022-34989 | CRITICAL | 9.8 | 0.9% | Jul 26, 2022 | Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_passwo... |
| CVE-2022-34988 | MEDIUM | 5.4 | 0.5% | Jul 26, 2022 | Inout Blockchain AltExchanger v1.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the compon... |
| CVE-2022-34067 | HIGH | 7.5 | 0.8% | Jul 26, 2022 | Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter. |
| CVE-2022-33745 | HIGH | 8.8 | 0.3% | Jul 26, 2022 | insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF ... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now