Latest CVE Feed
-
3.7
LOWCVE-2022-3375
An issue has been discovered in GitLab affecting all versions starting from 11.10 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. It was possible to disclose the branch names when attacker has... Read more
Affected Products : gitlab- Published: Apr. 05, 2023
- Modified: Feb. 10, 2025
-
3.7
LOWCVE-2024-34079
octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike the resource utilization of the STS service, and combined with a significant traffic volume could potentially lead to a denial of servi... Read more
Affected Products :- Published: May. 14, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2011-4316
Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, in certain unspecified conditions, does not lock the desktop screen between SPICE sessions, which allows local users with access to a virtual machine to gain access to other users' desktop ses... Read more
Affected Products : enterprise_virtualization_manager- Published: Jan. 04, 2013
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2001-0627
vi as included with SCO OpenServer 5.0 - 5.0.6 allows a local attacker to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : openserver- Published: Aug. 22, 2001
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2001-0317
Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process.... Read more
Affected Products : linux_kernel- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2005-1768
Race condition in the ia32 compatibility code for the execve system call in Linux kernel 2.4 before 2.4.31 and 2.6 before 2.6.6 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a concurrent thread that... Read more
Affected Products : linux_kernel- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2024-22403
Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an authorization code they could authenticate at any time using the code. As of version 28.0.0 OAuth codes are i... Read more
- Published: Jan. 18, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2013-0219
System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.... Read more
- Published: Feb. 24, 2013
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2012-1720
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier, when running on Solaris, allows local users to affect confident... Read more
- Published: Jun. 16, 2012
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2012-5659
Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment v... Read more
Affected Products : automatic_bug_reporting_tool- Published: Mar. 12, 2013
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2013-0404
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kernel/Boot.... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2025-24432
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race... Read more
- Published: Feb. 11, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Race Condition
-
3.7
LOWCVE-2025-48015
Failed login response could be different depending on whether the username was local or central.... Read more
Affected Products :- Published: May. 20, 2025
- Modified: May. 21, 2025
- Vuln Type: Information Disclosure
-
3.7
LOWCVE-2025-24430
Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race... Read more
- Published: Feb. 11, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Race Condition
-
3.7
LOWCVE-2025-50065
Vulnerability in the Oracle GraalVM for JDK product of Oracle Java SE (component: Native Image). The supported version that is affected is Oracle GraalVM for JDK: 24.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network ac... Read more
Affected Products : graalvm_for_jdk- Published: Jul. 15, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Denial of Service
-
3.7
LOWCVE-2025-54999
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, when using OpenBao's userpass auth method, user enumeration was possible due to timin... Read more
Affected Products : openbao- Published: Aug. 09, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
3.7
LOWCVE-2025-54787
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM version 7.14.6 which allows unauthenticated downloads of any file from the upload-directory, as long as it is na... Read more
Affected Products : suitecrm- Published: Aug. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
3.7
LOWCVE-2025-53857
Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to get channel subscription details without proper access to the channel via API call to the GET autocomplete/GetChannelSubscriptions e... Read more
Affected Products :- Published: Aug. 11, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
3.7
LOWCVE-2025-42988
Under certain conditions, SAP Business Objects Business Intelligence Platform allows an unauthenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. This disclosure of information could further enable t... Read more
Affected Products :- Published: Jun. 10, 2025
- Modified: Jun. 12, 2025
- Vuln Type: Information Disclosure
-
3.7
LOWCVE-2025-54352
WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Supplier is not changing this behavior.... Read more
Affected Products : wordpress- Published: Jul. 21, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Information Disclosure