Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2022-05-18 CVE-2021-42700 Unspecified vulnerability in Inkscape 0.91
Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information.
local
low complexity
inkscape
3.3
2022-05-18 CVE-2021-42702 Unspecified vulnerability in Inkscape 0.91
Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized information.
local
low complexity
inkscape
3.3
2022-05-16 CVE-2022-1722 Server-Side Request Forgery (SSRF) vulnerability in Diagrams Drawio
SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5.
local
low complexity
diagrams CWE-918
3.3
2022-05-12 CVE-2022-0005 Cleartext Transmission of Sensitive Information vulnerability in Intel products
Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to potentially enable information disclosure via physical access.
low complexity
intel CWE-319
2.4
2022-05-11 CVE-2022-28252 Out-of-bounds Read vulnerability in Adobe products
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure.
local
low complexity
adobe CWE-125
3.3
2022-05-11 CVE-2021-26342 Unspecified vulnerability in AMD products
In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB).
local
low complexity
amd
3.3
2022-05-11 CVE-2022-1426 Improper Authentication vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
high complexity
gitlab CWE-287
3.7
2022-05-09 CVE-2022-28162 Cleartext Storage of Sensitive Information vulnerability in Broadcom Sannav 2.1.0/2.1.1/2.1.1.8
Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text.
local
low complexity
broadcom CWE-312
3.3
2022-05-06 CVE-2021-27751 Insufficient Session Expiration vulnerability in Hcltechsw HCL Commerce
HCL Commerce is affected by an Insufficient Session Expiration vulnerability.
local
low complexity
hcltechsw CWE-613
3.3
2022-05-03 CVE-2022-28784 Path Traversal vulnerability in Google Android 10.0/11.0/12.0
Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user.
local
low complexity
google CWE-22
3.3