Latest CVE Feed
-
3.8
LOWCVE-2023-52584
In the Linux kernel, the following vulnerability has been resolved: spmi: mediatek: Fix UAF on device remove The pmif driver data that contains the clocks is allocated along with spmi_controller. On device remove, spmi_controller will be freed first, an... Read more
Affected Products : linux_kernel- Published: Mar. 06, 2024
- Modified: Mar. 14, 2025
-
3.8
LOWCVE-2023-42235
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple parameters of /monitor/s_normalizedtrans.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42242
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /monitor/s_terminal.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42236
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /common/ajaxfunction.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42238
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_eps.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42240
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /monitor/s_scheduledfile.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2022-2307
A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Acces... Read more
Affected Products : gitlab- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2023-42241
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_anagraphic.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2025-6943
Secret Server version 11.7 and earlier is vulnerable to a SQL report creation vulnerability that allows an administrator to gain access to restricted tables.... Read more
Affected Products : secret_server- Published: Jul. 02, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authorization
-
3.8
LOWCVE-2024-6156
Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.... Read more
Affected Products : lxd- Published: Dec. 06, 2024
- Modified: Aug. 26, 2025
-
3.8
LOWCVE-2023-42239
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_ep.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42237
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i_command.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2016-3159
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by le... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
3.8
LOWCVE-2013-1530
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability via unknown vectors related to Kernel.... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.8
LOWCVE-2017-7995
Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project cons... Read more
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
3.8
LOWCVE-2025-53971
Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role modifications which allows Team Admins to demote Team Members to Guests via the PUT /api/v4/teams/team-id/members/user-id/schemeRoles API ... Read more
Affected Products : mattermost_server- Published: Aug. 21, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authorization
-
3.8
LOWCVE-2024-6219
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.... Read more
Affected Products : lxd- Published: Dec. 06, 2024
- Modified: Aug. 28, 2025
-
3.8
LOWCVE-2020-8956
Pulse Secure Desktop Client 9.0Rx before 9.0R5 and 9.1Rx before 9.1R4 on Windows reveals users' passwords if Save Settings is enabled.... Read more
- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2022-23721
PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can lead to a username collision when two people with the same username are provisioned onto the same machine at different times.... Read more
Affected Products : pingid_integration_for_windows_login- Published: Apr. 25, 2023
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-39156
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=add.... Read more
- Published: Jun. 27, 2024
- Modified: Apr. 15, 2025