Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2022-03-25 CVE-2022-24784 Information Exposure Through Discrepancy vulnerability in Statamic
Statamic is a Laravel and Git powered CMS.
network
high complexity
statamic CWE-203
3.7
2022-03-23 CVE-2021-27456 Insecure Storage of Sensitive Information vulnerability in Phillips products
Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access control.
low complexity
phillips CWE-922
2.4
2022-03-23 CVE-2022-0861 XXE vulnerability in Mcafee Epolicy Orchestrator
A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a remote administrator attacker to upload a malicious XML file through the extension import functionality.
network
low complexity
mcafee CWE-611
3.8
2022-03-21 CVE-2022-24236 Incorrect Permission Assignment for Critical Resource vulnerability in Snapt Aria 12.8
An insecure permissions vulnerability in Snapt Aria v12.8 allows unauthenticated attackers to send e-mails from spoofed users' accounts.
network
low complexity
snapt CWE-732
3.5
2022-03-18 CVE-2022-22598 Unspecified vulnerability in Apple Iphone OS
An issue with app access to camera metadata was addressed with improved logic.
local
low complexity
apple
3.3
2022-03-18 CVE-2022-22599 Unspecified vulnerability in Apple products
Description: A permissions issue was addressed with improved validation.
low complexity
apple
2.4
2022-03-18 CVE-2022-22656 Improper Authentication vulnerability in Apple mac OS X and Macos
An authentication issue was addressed with improved state management.
local
low complexity
apple CWE-287
3.3
2022-03-18 CVE-2022-22670 Unspecified vulnerability in Apple products
An access issue was addressed with improved access restrictions.
local
low complexity
apple
3.3
2022-03-16 CVE-2022-26354 A flaw was found in the vhost-vsock device of QEMU.
local
low complexity
qemu debian
3.2
2022-03-14 CVE-2022-22348 Cross-Site Request Forgery (CSRF) vulnerability in IBM Spectrum Protect Operations Center
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to reverse tabnabbing where it could allow a page linked to from within Operations Center to rewrite it.
network
low complexity
ibm CWE-352
2.4