2022 CVE Vulnerabilities

27,543 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-26307HIGH8.8LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passw...
CVE-2022-26306HIGH7.5LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passw...
CVE-2022-26305HIGH7.5An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a tru...
CVE-2022-2523MEDIUM6.1Cross-site Scripting (XSS) - Reflected in GitHub repository beancount/fava prior to 1.22.2.
CVE-2022-2522HIGH7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061.
CVE-2022-2514MEDIUM6.1The time and filter parameters in Fava prior to v1.22 are vulnerable to reflected XSS due to the lack of escaping of err...
CVE-2022-21802MEDIUM6.1The package grapesjs before 0.19.5 are vulnerable to Cross-site Scripting (XSS) due to an improper sanitization of the c...
CVE-2022-1314HIGH8.8Type confusion in V8 in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap corru...
CVE-2022-1313HIGH8.8Use after free in tab groups in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit he...
CVE-2022-1312CRITICAL9.6Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed an attacker who convinced a user to install a ...
CVE-2022-1311HIGH8.8Use after free in shell in Google Chrome on ChromeOS prior to 100.0.4896.88 allowed a remote attacker to potentially exp...
CVE-2022-1310HIGH8.8Use after free in regular expressions in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially e...
CVE-2022-1309CRITICAL9.6Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to ...
CVE-2022-1308HIGH8.8Use after free in BFCache in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap ...
CVE-2022-1307MEDIUM4.3Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88 allowed a remote attacker...
CVE-2022-1306MEDIUM4.3Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to spoof t...
CVE-2022-1305HIGH8.8Use after free in storage in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially exploit heap ...
CVE-2022-1232HIGH8.8Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corru...
CVE-2022-0670CRITICAL9.1A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manil...
CVE-2022-2341MEDIUM4.8The Simple Page Transition WordPress plugin through 1.4.1 does not sanitise and escape some of its settings, which could...
CVE-2022-2340MEDIUM4.8The W-DALIL WordPress plugin through 2.0 does not sanitise and escape some of its fields, which could allow high privile...
CVE-2022-2299MEDIUM5.4The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a ro...
CVE-2022-2240HIGH8.8The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing unauthenticated users ...
CVE-2022-2239MEDIUM4.8The Request a Quote WordPress plugin before 2.3.9 does not sanitise and escape some of its settings, allowing high privi...
CVE-2022-2219HIGH7.2The Unyson WordPress plugin before 2.7.27 does not sanitise and escape a parameter before outputting it back in the page...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now