Latest CVE Feed
-
3.9
LOWCVE-2025-44964
A lack of SSL certificate validation in BlueStacks v5.20 allows attackers to execute a man-it-the-middle attack and obtain sensitive information.... Read more
Affected Products : bluestacks- Published: Aug. 05, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Cryptography
-
3.9
LOWCVE-2025-32004
Improper input validation in the Intel Edger8r Tool for some Intel(R) SGX SDK may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Authorization
-
3.9
LOWCVE-2019-0127
Logic error in the installer for Intel(R) OpenVINO(TM) 2018 R3 and before for Linux may allow a privileged user to potentially enable information disclosure via local access.... Read more
- Published: Feb. 18, 2019
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2025-1939
Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability aff... Read more
Affected Products : firefox- Published: Mar. 04, 2025
- Modified: Sep. 08, 2025
- Vuln Type: Misconfiguration
-
3.9
LOWCVE-2023-6690
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by making a GraphQL mutation to alter repository permissions during the transfer. This vulnerability affected GitHub Enterprise Serv... Read more
Affected Products : enterprise_server- Published: Dec. 21, 2023
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2017-17149
Huawei HiWallet App with the versions before 8.0.4 has an arbitrary lock pattern change vulnerability. It needs to verify the user's Huawei ID during lock pattern change. An attacker with root privilege who gets a user's smart phone may bypass Huawei ID v... Read more
Affected Products : hiwallet- Published: Mar. 09, 2018
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2025-1693
The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database cluster contents can inject control characters into the shell output. This may result in the display of falsified messages that appear to ... Read more
Affected Products : mongosh- Published: Feb. 27, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Injection
-
3.9
LOWCVE-2024-38806
Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not have. This can ... Read more
Affected Products :- Published: Jul. 18, 2024
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2020-1738
A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All... Read more
- Published: Mar. 16, 2020
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2024-12970
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection.This issue affects Pardus OS My Computer: before 0.7.2.... Read more
- Published: Jan. 06, 2025
- Modified: Jan. 06, 2025
- Vuln Type: Injection
-
3.9
LOWCVE-2022-21298
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Install). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris execute... Read more
- Published: Jan. 19, 2022
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2025-44657
In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauthorized access to system files, privilege escalation, or use of the compromised server as a pivot point for i... Read more
- Published: Jul. 21, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Misconfiguration
-
3.9
LOWCVE-2020-29443
ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.... Read more
- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2017-9635
Schneider Electric Ampla MES 6.4 provides capability to configure users and their privileges. When Ampla MES users are configured to use Simple Security, a weakness in the password hashing algorithm could be exploited to reverse the user's password. Schne... Read more
Affected Products : ampla_manufacturing_execution_system- Published: May. 18, 2018
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-20920
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris ex... Read more
- Published: Jan. 16, 2024
- Modified: Jun. 20, 2025
-
3.8
LOWCVE-2024-21000
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with net... Read more
Affected Products : active_iq_unified_manager oncommand_insight oncommand_workflow_automation snapcenter mysql_server- Published: Apr. 16, 2024
- Modified: Nov. 27, 2024
-
3.8
LOWCVE-2017-7995
Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project cons... Read more
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
3.8
LOWCVE-2019-12068
In QEMU 1:4.1-1, 1:2.1+dfsg-12+deb8u6, 1:2.8+dfsg-6+deb9u8, 1:3.1+dfsg-8~deb10u1, 1:3.1+dfsg-8+deb10u2, and 1:2.1+dfsg-12+deb8u12 (fixed), when executing script in lsi_execute_script(), the LSI scsi adapter emulator advances 's->dsp' index to read next op... Read more
- Published: Sep. 24, 2019
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-53502
Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.... Read more
Affected Products : semcms- Published: Dec. 03, 2024
- Modified: Apr. 04, 2025
-
3.8
LOWCVE-2023-27307
Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.... Read more
Affected Products : thunderbolt_dch_driver- Published: Feb. 14, 2024
- Modified: Nov. 21, 2024