Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2022-06-07 CVE-2022-28794 Exposure of Resource to Wrong Sphere vulnerability in Google Android 10.0/11.0/12.0
Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information.
local
low complexity
google CWE-668
3.3
2022-06-07 CVE-2022-30714 Exposure of Resource to Wrong Sphere vulnerability in Google Android 10.0/11.0/12.0
Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.
local
low complexity
google CWE-668
3.3
2022-06-06 CVE-2022-1783 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.3 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1.
network
low complexity
gitlab
2.7
2022-06-05 CVE-2022-32296 Use of Insufficiently Random Values vulnerability in Linux Kernel
The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used.
local
low complexity
linux CWE-330
3.3
2022-05-26 CVE-2022-26703 Unspecified vulnerability in Apple Iphone OS
An authorization issue was addressed with improved state management.
low complexity
apple
2.4
2022-05-25 CVE-2022-29253 Path Traversal vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-22
2.7
2022-05-20 CVE-2022-29160 Incomplete Cleanup vulnerability in Nextcloud
Nextcloud Android is the Android client for Nextcloud, a self-hosted productivity platform.
local
low complexity
nextcloud CWE-459
3.3
2022-05-18 CVE-2021-42700 Unspecified vulnerability in Inkscape 0.91
Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized information.
local
low complexity
inkscape
3.3
2022-05-18 CVE-2021-42702 Unspecified vulnerability in Inkscape 0.91
Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized information.
local
low complexity
inkscape
3.3
2022-05-16 CVE-2022-1722 Server-Side Request Forgery (SSRF) vulnerability in Diagrams Drawio
SSRF in editor's proxy via IPv6 link-local address in GitHub repository jgraph/drawio prior to 18.0.5.
local
low complexity
diagrams CWE-918
3.3