Latest CVE Feed
-
3.8
LOWCVE-2023-29128
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The filename in the upload feature of the web based management of the affected device is susce... Read more
- Published: May. 09, 2023
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-0628
The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. This makes it possible for authenticated attackers, with administrator-level ac... Read more
Affected Products : wp_rss_aggregator- Published: Feb. 07, 2024
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2023-26592
Deserialization of untrusted data in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable a denial of service via local access.... Read more
Affected Products : thunderbolt_dch_driver- Published: Feb. 14, 2024
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-8160
Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command injection leading to being able to transfer files from/to the Axis device. This fla... Read more
Affected Products : axis_os- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
3.8
LOWCVE-2025-25228
A SQL injection in VirtueMart component 1.0.0 - 4.4.7 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands in the product management area in backend.... Read more
Affected Products : virtuemart- Published: Apr. 21, 2025
- Modified: May. 28, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2002-2202
Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email.... Read more
Affected Products : outlook_express- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
3.8
LOWCVE-2020-3951
VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) contain a denial-of-service vulnerability due to a heap-overflow issue in Cortado Thinprint. Attackers with non-administrative access to a guest VM with vi... Read more
- Published: Mar. 17, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-29196
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. There is a Path Traversal vulnerability in Attachments that allows attackers with admin rights to upload malicious files to other locations of the web r... Read more
Affected Products : phpmyfaq- Published: Mar. 26, 2024
- Modified: Jan. 09, 2025
-
3.8
LOWCVE-2020-3970
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in the Shader functionali... Read more
- Published: Jun. 25, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2013-2140
The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS users to cause a denial of service (data loss) via filesystem write operations on a read-only disk ... Read more
Affected Products : linux_kernel- Published: Sep. 25, 2013
- Modified: Apr. 11, 2025
-
3.8
LOWCVE-2020-8956
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.... Read more
- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2013-3792
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.18, 4.0.20, 4.1.28, and 4.2.18 allows local users to affect availability via unknown vectors related to Core.... Read more
Affected Products : vm_virtualbox- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
3.8
LOWCVE-2020-13523
An exploitable information disclosure vulnerability exists in SoftPerfect’s RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can cause the disclosure of sensitive information. An attacker can send a malicious IRP to trigger this... Read more
Affected Products : ram_disk- Published: Aug. 04, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2015-2651
Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect availability via vectors related to Kernel Zones virtualized NIC driver.... Read more
Affected Products : solaris- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
3.8
LOWCVE-2020-6197
SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download the portables.... Read more
Affected Products : enable_now- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2025-25878
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /del.php. The attack can use SQL injection to obtain sensitive data.... Read more
Affected Products : simple_chatbox- Published: Feb. 21, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2020-11947
iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process memory to an attacker.... Read more
Affected Products : qemu- Published: Dec. 31, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2020-25082
An attacker with physical access to Nuvoton Trusted Platform Module (NPCT75x 7.2.x before 7.2.2.0) could extract an Elliptic Curve Cryptography (ECC) private key via a side-channel attack against ECDSA, because of an Observable Timing Discrepancy.... Read more
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-21247
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker wi... Read more
- Published: Oct. 15, 2024
- Modified: Mar. 13, 2025
-
3.8
LOWCVE-2023-0091
A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information.... Read more
- Published: Jan. 13, 2023
- Modified: Apr. 09, 2025