CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2022-0470

    Last Modified: 21 Nov 2024

    Out of bounds memory access in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0469

    Last Modified: 21 Nov 2024

    Use after free in Cast in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific interactions to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0468

    Last Modified: 21 Nov 2024

    Use after free in Payments in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0467

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Pointer Lock in Google Chrome on Windows prior to 98.0.4758.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 5 Apr 2022
    9.6
    Critical

    CVE-2022-0466

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Extensions Platform in Google Chrome prior to 98.0.4758.80 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0465

    Last Modified: 21 Nov 2024

    Use after free in Extensions in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via user interaction.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0464

    Last Modified: 21 Nov 2024

    Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0463

    Last Modified: 21 Nov 2024

    Use after free in Accessibility in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2022-0462

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Scroll in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2022-0461

    Last Modified: 21 Nov 2024

    Policy bypass in COOP in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to bypass iframe sandbox via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0460

    Last Modified: 21 Nov 2024

    Use after free in Window Dialogue in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0459

    Last Modified: 21 Nov 2024

    Use after free in Screen Capture in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who had compromised the renderer process and convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0458

    Last Modified: 21 Nov 2024

    Use after free in Thumbnail Tab Strip in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0457

    Last Modified: 21 Nov 2024

    Type confusion in V8 in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0456

    Last Modified: 21 Nov 2024

    Use after free in Web Search in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via profile destruction.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2022-0455

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 98.0.4758.80 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0454

    Last Modified: 21 Nov 2024

    Heap buffer overflow in ANGLE in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0453

    Last Modified: 21 Nov 2024

    Use after free in Reader Mode in Google Chrome prior to 98.0.4758.80 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    9.6
    Critical

    CVE-2022-0452

    Last Modified: 21 Nov 2024

    Use after free in Safe Browsing in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

    Published: 5 Apr 2022
    7.5
    High

    CVE-2022-26619

    Last Modified: 21 Nov 2024

    Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0809

    Last Modified: 21 Nov 2024

    Out of bounds memory access in WebXR in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0808

    Last Modified: 21 Nov 2024

    Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in a series of user interaction to potentially exploit heap corruption via user interactions.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2022-0807

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2022-0806

    Last Modified: 21 Nov 2024

    Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0805

    Last Modified: 21 Nov 2024

    Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2022-0804

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2022-0803

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2022-0802

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0800

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0799

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege escalation via a crafted offline installer file.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0798

    Last Modified: 21 Nov 2024

    Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0797

    Last Modified: 21 Nov 2024

    Out of bounds memory access in Mojo in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0796

    Last Modified: 21 Nov 2024

    Use after free in Media in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0795

    Last Modified: 21 Nov 2024

    Type confusion in Blink Layout in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0794

    Last Modified: 21 Nov 2024

    Use after free in WebShare in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0793

    Last Modified: 21 Nov 2024

    Use after free in Cast in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension and engage in specific user interaction to potentially exploit heap corruption via a crafted Chrome Extension.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2022-0792

    Last Modified: 21 Nov 2024

    Out of bounds read in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0791

    Last Modified: 21 Nov 2024

    Use after free in Omnibox in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via user interactions.

    Published: 5 Apr 2022
    9.6
    Critical

    CVE-2022-0790

    Last Modified: 21 Nov 2024

    Use after free in Cast UI in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially perform a sandbox escape via a crafted HTML page.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-0789

    Last Modified: 21 Nov 2024

    Heap buffer overflow in ANGLE in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 5 Apr 2022
    9.8
    Critical

    CVE-2022-26585

    Last Modified: 21 Nov 2024

    Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.

    Published: 5 Apr 2022
    8.8
    High

    CVE-2022-23732

    Last Modified: 21 Nov 2024

    A path traversal vulnerability was identified in GitHub Enterprise Server management console that allowed the bypass of CSRF protections. This could potentially lead to privilege escalation. To exploit this vulnerability, an attacker would need to target a user that was actively logged into the management console. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.5 and was fixed in versions 3.1.19, 3.2.11, 3.3.6, 3.4.1. This vulnerability was reported via the GitHub Bug Bounty program.

    Published: 5 Apr 2022
    7.2
    High

    CVE-2022-26986

    Last Modified: 21 Nov 2024

    SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system.

    Published: 5 Apr 2022
    5.5
    Medium

    CVE-2023-1637

    Last Modified: 19 Feb 2025

    A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks in the Linux kernel X86 CPU Power management options functionality was found in the way user resuming CPU from suspend-to-RAM. A local user could use this flaw to potentially get unauthorized access to some memory of the CPU similar to the speculative execution behavior kind of attacks.

    Published: 5 Apr 2022
    5.4
    Medium

    CVE-2022-1197

    Last Modified: 16 Apr 2025

    When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was not yet revoked, and the existing key was kept as non-revoked. Revocation statements that used another revocation reason, or that didn't specify a revocation reason, were unaffected. This vulnerability affects Thunderbird < 91.8.

    Published: 5 Apr 2022
    7.8
    High

    CVE-2022-26358

    Last Modified: 21 Nov 2024

    IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for platform tasks such as legacy USB emulation. Since the precise purpose of these regions is unknown, once a device associated with such a region is active, the mappings of these regions need to remain continuouly accessible by the device. This requirement has been violated. Subsequent DMA or interrupts from the device may have unpredictable behaviour, ranging from IOMMU faults to memory corruption.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2022-28285

    Last Modified: 16 Apr 2025

    When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

    Published: 5 Apr 2022
    5.4
    Medium

    CVE-2022-28286

    Last Modified: 16 Apr 2025

    Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2022-1196

    Last Modified: 16 Apr 2025

    After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8 and Firefox ESR < 91.8.

    Published: 5 Apr 2022
    6.5
    Medium

    CVE-2022-1097

    Last Modified: 16 Apr 2025

    <code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

    Published: 5 Apr 2022