Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2024-01-04 CVE-2024-22047 Race Condition vulnerability in Collectiveidea Audited
A race condition exists in Audited 4.0.0 to 5.3.3 that can result in an authenticated user to cause audit log entries to be attributed to another user.
network
high complexity
collectiveidea CWE-362
3.1
2024-01-04 CVE-2024-20807 Unspecified vulnerability in Samsung Email 6.1.82.0
Implicit intent hijacking vulnerability in Samsung Email prior to version 6.1.90.16 allows local attacker to get sensitive information.
local
low complexity
samsung
3.3
2024-01-03 CVE-2024-0217 Use After Free vulnerability in multiple products
A use-after-free flaw was found in PackageKitd.
3.3
2024-01-02 CVE-2020-26623 SQL Injection vulnerability in Gilacms Gila CMS
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.
network
low complexity
gilacms CWE-89
3.8
2024-01-02 CVE-2020-26624 SQL Injection vulnerability in Gilacms Gila CMS
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.
network
low complexity
gilacms CWE-89
3.8
2024-01-02 CVE-2020-26625 SQL Injection vulnerability in Gilacms Gila CMS
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.
network
low complexity
gilacms CWE-89
3.8
2024-01-02 CVE-2023-49142 Use After Free vulnerability in Openharmony
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia audio crash through modify a released pointer.
local
low complexity
openharmony CWE-416
3.3
2023-12-31 CVE-2023-52275 Missing Authorization vulnerability in Tecno-Mobile Camon X Firmware
Gallery3d on Tecno Camon X CA7 devices allows attackers to view hidden images by navigating to data/com.android.gallery3d/.privatealbum/.encryptfiles and guessing the correct image file extension.
low complexity
tecno-mobile CWE-862
2.1
2023-12-22 CVE-2023-51386 Improper Privilege Management vulnerability in Amazon Awslabs Sandbox Accounts for Events
Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI.
local
low complexity
amazon CWE-269
3.3
2023-12-22 CVE-2023-51651 Path Traversal vulnerability in Amazon AWS Software Development KIT
AWS SDK for PHP is the Amazon Web Services software development kit for PHP.
local
low complexity
amazon CWE-22
3.3