CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-1919

    Last Modified: 21 Nov 2024

    Use after free in Codecs in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2477

    Last Modified: 21 Nov 2024

    Use after free in Guest View in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2478

    Last Modified: 21 Nov 2024

    Use after free in PDF in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 28 Jul 2022
    4.3
    Medium

    CVE-2022-2479

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in File in Google Chrome on Android prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious app to obtain potentially sensitive information from internal file directories via a crafted HTML page.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2480

    Last Modified: 21 Nov 2024

    Use after free in Service Worker API in Google Chrome prior to 103.0.5060.134 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 28 Jul 2022
    5.4
    Medium

    CVE-2022-29360

    Last Modified: 21 Nov 2024

    The Email Viewer in RainLoop through 1.6.0 allows XSS via a crafted email message.

    Published: 28 Jul 2022
    7.5
    High

    CVE-2022-34568

    Last Modified: 21 Nov 2024

    SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11yuv.c.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2294

    Last Modified: 24 Oct 2025

    Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 28 Jul 2022
    8.8
    High

    CVE-2022-2481

    Last Modified: 21 Nov 2024

    Use after free in Views in Google Chrome prior to 103.0.5060.134 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via UI interaction.

    Published: 28 Jul 2022
    5.4
    Medium

    CVE-2022-34140

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.

    Published: 27 Jul 2022
    5.5
    Medium

    CVE-2022-34009

    Last Modified: 21 Nov 2024

    Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly handle the absence of this file after Windows Defender has flagged it as malware.

    Published: 27 Jul 2022
    5.4
    Medium

    CVE-2021-33371

    Last Modified: 22 Apr 2025

    A stored cross-site scripting (XSS) vulnerability in /nav_bar_action.php of Student Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Chat box.

    Published: 27 Jul 2022
    6.5
    Medium

    CVE-2021-46830

    Last Modified: 21 Nov 2024

    A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a specific username and/or profile information to gain access to files at a higher directory level than intended.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-1876

    Last Modified: 21 Nov 2024

    Heap buffer overflow in DevTools in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

    Published: 27 Jul 2022
    4.3
    Medium

    CVE-2022-1875

    Last Modified: 21 Nov 2024

    Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-1874

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Safe Browsing in Google Chrome on Mac prior to 102.0.5005.61 allowed a remote attacker to bypass downloads protection policy via a crafted HTML page.

    Published: 27 Jul 2022
    6.5
    Medium

    CVE-2022-1873

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in COOP in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 27 Jul 2022
    4.3
    Medium

    CVE-2022-1872

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass downloads policy via a crafted HTML page.

    Published: 27 Jul 2022
    4.3
    Medium

    CVE-2022-1871

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass file system policy via a crafted HTML page.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-1870

    Last Modified: 21 Nov 2024

    Use after free in App Service in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

    Published: 27 Jul 2022
    6.5
    Medium

    CVE-2022-1869

    Last Modified: 21 Nov 2024

    Type Confusion in V8 in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 27 Jul 2022
    6.5
    Medium

    CVE-2022-1868

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Extensions API in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page.

    Published: 27 Jul 2022
    6.5
    Medium

    CVE-2022-1867

    Last Modified: 21 Nov 2024

    Insufficient validation of untrusted input in Data Transfer in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to bypass same origin policy via a crafted clipboard content.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-1866

    Last Modified: 21 Nov 2024

    Use after free in Tablet Mode in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific user interactions.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-1865

    Last Modified: 21 Nov 2024

    Use after free in Bookmarks in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-1864

    Last Modified: 21 Nov 2024

    Use after free in WebApp Installs in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-1863

    Last Modified: 21 Nov 2024

    Use after free in Tab Groups in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension and specific user interaction.

    Published: 27 Jul 2022
    6.5
    Medium

    CVE-2022-1862

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Extensions in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to bypass profile restrictions via a crafted HTML page.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-1861

    Last Modified: 21 Nov 2024

    Use after free in Sharing in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific user interaction.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-1860

    Last Modified: 21 Nov 2024

    Use after free in UI Foundations in Google Chrome on Chrome OS prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific user interactions.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-1859

    Last Modified: 21 Nov 2024

    Use after free in Performance Manager in Google Chrome prior to 102.0.5005.61 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

    Published: 27 Jul 2022
    6.5
    Medium

    CVE-2022-1858

    Last Modified: 21 Nov 2024

    Out of bounds read in DevTools in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to perform an out of bounds memory read via specific user interaction.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-1857

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in File System API in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to bypass file system restrictions via a crafted HTML page.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-1856

    Last Modified: 21 Nov 2024

    Use after free in User Education in Google Chrome prior to 102.0.5005.61 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension or specific user interaction.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-1855

    Last Modified: 21 Nov 2024

    Use after free in Messaging in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 27 Jul 2022
    8.8
    High

    CVE-2022-1854

    Last Modified: 21 Nov 2024

    Use after free in ANGLE in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 27 Jul 2022
    9.6
    Critical

    CVE-2022-1853

    Last Modified: 21 Nov 2024

    Use after free in Indexed DB in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

    Published: 27 Jul 2022
    5.4
    Medium

    CVE-2022-36948

    Last Modified: 21 Nov 2024

    In Veritas NetBackup OpsCenter, a DOM XSS attack can occur. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

    Published: 27 Jul 2022
    9.3
    Critical

    CVE-2022-36949

    Last Modified: 21 Nov 2024

    In Veritas NetBackup OpsCenter, an attacker with local access to a NetBackup OpsCenter server could potentially escalate their privileges. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

    Published: 27 Jul 2022
    9.8
    Critical

    CVE-2022-36950

    Last Modified: 21 Nov 2024

    In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may be able to perform remote command execution through a Java classloader manipulation. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

    Published: 27 Jul 2022
    9.8
    Critical

    CVE-2022-36951

    Last Modified: 21 Nov 2024

    In Veritas NetBackup OpsCenter, an unauthenticated remote attacker may compromise the host by exploiting an incorrectly patched vulnerability. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

    Published: 27 Jul 2022
    8.4
    High

    CVE-2022-36952

    Last Modified: 21 Nov 2024

    In Veritas NetBackup OpsCenter, a hard-coded credential exists that could be used to exploit the underlying VxSS subsystem. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

    Published: 27 Jul 2022
    4.3
    Medium

    CVE-2022-36953

    Last Modified: 21 Nov 2024

    In Veritas NetBackup OpsCenter, certain endpoints could allow an unauthenticated remote attacker to gain sensitive information. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

    Published: 27 Jul 2022
    9.9
    Critical

    CVE-2022-36954

    Last Modified: 21 Nov 2024

    In Veritas NetBackup OpsCenter, under specific conditions, an authenticated remote attacker may be able to create or modify OpsCenter user accounts. This affects 8.x through 8.3.0.2, 9.x through 9.0.0.1, 9.1.x through 9.1.0.1, and 10.

    Published: 27 Jul 2022
    7.8
    High

    CVE-2022-36955

    Last Modified: 21 Nov 2024

    In Veritas NetBackup, an attacker with unprivileged local access to a NetBackup Client may send specific commands to escalate their privileges. This affects 8.0 through 8.1.2, 8.2, 8.3 through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1.

    Published: 27 Jul 2022
    9
    Critical

    CVE-2022-36956

    Last Modified: 21 Nov 2024

    In Veritas NetBackup, the NetBackup Client allows arbitrary command execution from any remote host that has access to a valid host-id NetBackup certificate/private key from the same domain. The affects 9.0.x through 9.0.0.1 and 9.1.x through 9.1.0.1.

    Published: 27 Jul 2022
    7.3
    High

    CVE-2021-38410

    Last Modified: 17 Apr 2025

    AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.

    Published: 27 Jul 2022
    5.3
    Medium

    CVE-2021-42535

    Last Modified: 17 Apr 2025

    VISAM VBASE version 11.6.0.6 does not neutralize or incorrectly neutralizes user-controllable input before the data is placed in output used as a public-facing webpage.

    Published: 27 Jul 2022
    7.4
    High

    CVE-2021-38417

    Last Modified: 17 Apr 2025

    VISAM VBASE version 11.6.0.6 is vulnerable to improper access control via the web-remote endpoint, which may allow an unauthenticated user viewing access to folders and files in the directory listing.

    Published: 27 Jul 2022
    5.9
    Medium

    CVE-2021-42537

    Last Modified: 17 Apr 2025

    VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

    Published: 27 Jul 2022