Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2023-02-16 CVE-2022-29054 Unspecified vulnerability in Fortinet Fortios and Fortiproxy
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x and 6.0.x may allow an attacker in possession of the encrypted key to decipher it.
local
low complexity
fortinet
3.3
2023-02-16 CVE-2022-48307 Improper Certificate Validation vulnerability in Palantir Magritte-Ftp
It was discovered that the Magritte-ftp was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API.
network
high complexity
palantir CWE-295
3.7
2023-02-16 CVE-2022-48308 Improper Certificate Validation vulnerability in Palantir Sls-Logging
It was discovered that the sls-logging was not verifying hostnames in TLS certificates due to a misuse of the javax.net.ssl.SSLSocketFactory API.
network
high complexity
palantir CWE-295
3.7
2023-02-15 CVE-2023-23847 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Synopsys Coverity
A cross-site request forgery (CSRF) vulnerability in Synopsys Jenkins Coverity Plugin 3.0.2 and earlier allows attackers to connect to an attacker-specified HTTP server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-352
3.5
2023-02-14 CVE-2023-23934 Unspecified vulnerability in Palletsprojects Werkzeug
Werkzeug is a comprehensive WSGI web application library.
low complexity
palletsprojects
3.5
2023-02-14 CVE-2023-24565 Out-of-bounds Read vulnerability in Siemens Solid Edge Se2023
A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (All versions < V223.0Update2).
local
low complexity
siemens CWE-125
3.3
2023-02-14 CVE-2023-24566 Stack-based Buffer Overflow vulnerability in Siemens Solid Edge Se2023
A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (All versions < V223.0Update2).
local
low complexity
siemens CWE-121
3.3
2023-02-13 CVE-2023-23697 Link Following vulnerability in Dell Command | Intel Vpro OUT of Band
Dell Command | Intel vPro Out of Band, versions before 4.4.0, contain an arbitrary folder delete vulnerability during uninstallation.
local
low complexity
dell CWE-59
3.3
2023-02-13 CVE-2023-24572 Link Following vulnerability in Dell Command | Integration Suite for System Center 6.2.0
Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerability during uninstallation.
local
low complexity
dell CWE-59
3.3
2023-02-12 CVE-2022-42436 Unspecified vulnerability in IBM MQ
IBM MQ 8.0.0, 9.0.0, 9.1.0, 9.2.0, 9.3.0 Managed File Transfer could allow a local user to obtain sensitive information from diagnostic files.
local
low complexity
ibm
3.3