Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2022-05-25 CVE-2022-29253 Path Traversal vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-22
2.7
2022-05-20 CVE-2022-29160 Incomplete Cleanup vulnerability in Nextcloud
Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform.
local
low complexity
nextcloud CWE-459
3.3
2022-05-18 CVE-2021-42700 Unspecified vulnerability in Inkscape 0.91
Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information.
local
low complexity
inkscape
3.3
2022-05-18 CVE-2021-42702 Unspecified vulnerability in Inkscape 0.91
Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized information.
local
low complexity
inkscape
3.3
2022-05-16 CVE-2022-1722 Server-Side Request Forgery (SSRF) vulnerability in Diagrams Drawio
SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5.
local
low complexity
diagrams CWE-918
3.3
2022-05-12 CVE-2022-0005 Cleartext Transmission of Sensitive Information vulnerability in Intel products
Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to potentially enable information disclosure via physical access.
low complexity
intel CWE-319
2.4
2022-05-11 CVE-2022-28252 Out-of-bounds Read vulnerability in Adobe products
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure.
local
low complexity
adobe CWE-125
3.3
2022-05-11 CVE-2021-26342 Unspecified vulnerability in AMD products
In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB).
local
low complexity
amd
3.3
2022-05-11 CVE-2022-1426 Improper Authentication vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1.
network
high complexity
gitlab CWE-287
3.7
2022-05-09 CVE-2022-28162 Cleartext Storage of Sensitive Information vulnerability in Broadcom Sannav 2.1.0/2.1.1/2.1.1.8
Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text.
local
low complexity
broadcom CWE-312
3.3