Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2022-04-11 CVE-2022-28778 Unspecified vulnerability in Samsung Security Supporter
Improper access control vulnerability in Samsung Security Supporter prior to version 1.2.40.0 allows attacker to set the arbitrary folder as Secret Folder without Samsung Security Supporter permission
local
low complexity
samsung
3.3
2022-04-11 CVE-2022-29035 Use of Insufficiently Random Values vulnerability in Jetbrains Ktor
In JetBrains Ktor Native before version 2.0.0 random values used for nonce generation weren't using SecureRandom implementations
network
low complexity
jetbrains CWE-330
2.7
2022-04-04 CVE-2022-1111 Unspecified vulnerability in Gitlab
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8 prior to 14.8.5, and 14.0 prior to 14.7.7 under certain conditions caused imported projects to show an incorrect user in the 'Access Granted' column in the project membership pages
network
low complexity
gitlab
2.7
2022-04-01 CVE-2021-20238 Missing Authentication for Critical Function vulnerability in Redhat products
It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication.
network
high complexity
redhat CWE-306
3.7
2022-03-31 CVE-2022-27049 Unspecified vulnerability in Raidrive
Raidrive before v2021.12.35 allows attackers to arbitrarily move log files by pre-creating a mountpoint and log files before Raidrive is installed.
local
low complexity
raidrive
2.0
2022-03-30 CVE-2020-35501 A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem
local
low complexity
linux redhat
3.4
2022-03-30 CVE-2021-39739 Information Exposure Through Log Files vulnerability in Google Android 12.1
In ArrayMap, there is a possible leak of the content of SMS messages due to log information disclosure.
local
low complexity
google CWE-532
3.3
2022-03-30 CVE-2022-1180 Unspecified vulnerability in Open-Emr Openemr
Reflected Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.
network
low complexity
open-emr
3.5
2022-03-29 CVE-2022-22935 Improper Authentication vulnerability in Saltstack Salt
An issue was discovered in SaltStack Salt in versions before 3002.8, 3003.4, 3004.1.
network
high complexity
saltstack CWE-287
3.7
2022-03-28 CVE-2018-25030 Race Condition vulnerability in Mirmay File Manager and Secure Private Browser
A vulnerability classified as problematic has been found in Mirmay Secure Private Browser and File Manager up to 2.5.
local
high complexity
mirmay CWE-362
2.5