Latest CVE Feed
-
3.9
LOWCVE-2024-38806
Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not have. This can ... Read more
Affected Products :- Published: Jul. 18, 2024
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2020-14263
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"... Read more
Affected Products : traveler_companion- Published: Oct. 21, 2021
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2022-21298
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Install). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris execute... Read more
- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2024-12970
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection.This issue affects Pardus OS My Computer: before 0.7.2.... Read more
- Published: Jan. 06, 2025
- Modified: Jan. 06, 2025
- Vuln Type: Injection
-
3.9
LOWCVE-2020-14264
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"... Read more
Affected Products : traveler_companion- Published: Oct. 25, 2021
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2020-13361
In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation.... Read more
- Published: May. 28, 2020
- Modified: Nov. 21, 2024
-
3.9
LOW- Published: Mar. 14, 2024
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2024-45616
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following problems were caus... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 13, 2024
-
3.9
LOWCVE-2024-45620
A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized part... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 19, 2024
-
3.9
LOWCVE-2024-45617
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 13, 2024
-
3.9
LOWCVE-2024-45618
A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. Insufficient or missing checking of return values of functions leads... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 13, 2024
-
3.9
LOWCVE-2024-45615
A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as arguments to other functions, etc.).... Read more
- Published: Sep. 03, 2024
- Modified: Sep. 13, 2024
-
3.8
LOWCVE-2024-46897
Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. A logged-in user with the permission of table management may obtain and/or alter the information of the unauthorized table.... Read more
Affected Products : exment- Published: Oct. 18, 2024
- Modified: Oct. 22, 2024
-
3.8
LOWCVE-2019-12068
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next op... Read more
- Published: Sep. 24, 2019
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2025-22449
Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by updating the "allow_open_invite" field via making their team public.... Read more
- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Authorization
-
3.8
LOWCVE-2024-34203
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguageCfg function.... Read more
- Published: May. 14, 2024
- Modified: Apr. 03, 2025
-
3.8
LOWCVE-2023-5159
Mattermost fails to properly verify the permissions when managing/updating a bot allowing a User Manager role with user edit permissions to manage/update bots. ... Read more
- Published: Sep. 29, 2023
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-30142
HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.... Read more
Affected Products : bigfix_compliance- Published: Nov. 07, 2024
- Modified: Jun. 17, 2025
-
3.8
LOWCVE-2020-26623
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.... Read more
Affected Products : gila_cms- Published: Jan. 02, 2024
- Modified: Jun. 03, 2025
-
3.8
LOWCVE-2020-26624
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.... Read more
Affected Products : gila_cms- Published: Jan. 02, 2024
- Modified: Jun. 17, 2025