Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2020-06-12 CVE-2020-4050 In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved.
network
high complexity
wordpress fedoraproject debian
3.1
2020-06-12 CVE-2020-4049 In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page.
network
low complexity
wordpress fedoraproject debian
2.4
2020-06-12 CVE-2020-3930 Information Exposure Through Log Files vulnerability in Geovision Gv-Gf192X Firmware 1.10
GeoVision Door Access Control device family improperly stores and controls access to system logs, any users can read these logs.
local
low complexity
geovision CWE-532
3.3
2020-06-09 CVE-2020-9848 Unspecified vulnerability in Apple Iphone OS
An authorization issue was addressed with improved state management.
low complexity
apple
2.4
2020-06-04 CVE-2020-13838 Missing Authentication for Critical Function vulnerability in Google Android 10.0/9.0
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software.
low complexity
google CWE-306
3.5
2020-06-04 CVE-2020-13837 Missing Authentication for Critical Function vulnerability in Google Android 10.0
An issue was discovered on Samsung mobile devices with Q(10.0) software.
low complexity
google CWE-306
3.5
2020-06-03 CVE-2020-5297 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Octobercms October
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, an attacker can exploit this vulnerability to upload jpg, jpeg, bmp, png, webp, gif, ico, css, js, woff, woff2, svg, ttf, eot, json, md, less, sass, scss, xml files to any directory of an October CMS server.
network
low complexity
octobercms CWE-610
2.7
2020-06-03 CVE-2020-3322 Improper Input Validation vulnerability in Cisco Webex Network Recording Player and Webex Player
A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system.
local
low complexity
cisco CWE-20
3.3
2020-06-03 CVE-2020-3321 Improper Input Validation vulnerability in Cisco Webex Network Recording Player and Webex Player
A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system.
local
low complexity
cisco CWE-20
3.3
2020-06-03 CVE-2020-3319 Improper Input Validation vulnerability in Cisco Webex Network Recording Player and Webex Player
A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system.
local
low complexity
cisco CWE-20
3.3