2022 CVE Vulnerabilities
27,543 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-26307 | HIGH | 8.8 | 1.1% | Jul 25, 2022 | LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passw... |
| CVE-2022-26306 | HIGH | 7.5 | 0.8% | Jul 25, 2022 | LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passw... |
| CVE-2022-26305 | HIGH | 7.5 | 1.0% | Jul 25, 2022 | An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a tru... |
| CVE-2022-2523 | MEDIUM | 6.1 | 0.7% | Jul 25, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2. |
| CVE-2022-2522 | HIGH | 7.8 | 0.5% | Jul 25, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061. |
| CVE-2022-2514 | MEDIUM | 6.1 | 0.7% | Jul 25, 2022 | The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of err... |
| CVE-2022-21802 | MEDIUM | 6.1 | 0.6% | Jul 25, 2022 | The package grapesjs before 0.19.5 are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the c... |
| CVE-2022-1314 | HIGH | 8.8 | 0.8% | Jul 25, 2022 | Type confusion in V8 in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2022-1313 | HIGH | 8.8 | 0.7% | Jul 25, 2022 | Use after free in tab groups in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit he... |
| CVE-2022-1312 | CRITICAL | 9.6 | 0.5% | Jul 25, 2022 | Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a ... |
| CVE-2022-1311 | HIGH | 8.8 | 0.7% | Jul 25, 2022 | Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exp... |
| CVE-2022-1310 | HIGH | 8.8 | 0.9% | Jul 25, 2022 | Use after free in regular expressions in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially e... |
| CVE-2022-1309 | CRITICAL | 9.6 | 0.7% | Jul 25, 2022 | Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to ... |
| CVE-2022-1308 | HIGH | 8.8 | 0.8% | Jul 25, 2022 | Use after free in BFCache in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap ... |
| CVE-2022-1307 | MEDIUM | 4.3 | 0.6% | Jul 25, 2022 | Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allowed a remote attacker... |
| CVE-2022-1306 | MEDIUM | 4.3 | 0.6% | Jul 25, 2022 | Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to spoof t... |
| CVE-2022-1305 | HIGH | 8.8 | 0.7% | Jul 25, 2022 | Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap ... |
| CVE-2022-1232 | HIGH | 8.8 | 16.5% | Jul 25, 2022 | Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2022-0670 | CRITICAL | 9.1 | 0.9% | Jul 25, 2022 | A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manil... |
| CVE-2022-2341 | MEDIUM | 4.8 | 0.6% | Jul 25, 2022 | The Simple Page Transition WordPress plugin through 1.4.1 does not sanitise and escape some of its settings, which could... |
| CVE-2022-2340 | MEDIUM | 4.8 | 0.6% | Jul 25, 2022 | The W-DALIL WordPress plugin through 2.0 does not sanitise and escape some of its fields, which could allow high privile... |
| CVE-2022-2299 | MEDIUM | 5.4 | 0.5% | Jul 25, 2022 | The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a ro... |
| CVE-2022-2240 | HIGH | 8.8 | 1.2% | Jul 25, 2022 | The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users ... |
| CVE-2022-2239 | MEDIUM | 4.8 | 0.5% | Jul 25, 2022 | The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privi... |
| CVE-2022-2219 | HIGH | 7.2 | 1.4% | Jul 25, 2022 | The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now