Latest CVE Feed
-
3.8
LOWCVE-2023-41044
Graylog is a free and open log management platform. A partial path traversal vulnerability exists in Graylog's `Support Bundle` feature. The vulnerability is caused by incorrect user input validation in an HTTP API resource. Graylog's Support Bundle featu... Read more
Affected Products : graylog- Published: Aug. 31, 2023
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2025-36581
Dell PowerEdge Platform version(s) 14G AMD BIOS v1.25.0 and prior, contain(s) an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information ... Read more
Affected Products :- Published: Aug. 14, 2025
- Modified: Aug. 15, 2025
- Vuln Type: Memory Corruption
-
3.8
LOWCVE-2013-1530
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability via unknown vectors related to Kernel.... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
3.8
LOWCVE-2007-1352
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.... Read more
Affected Products : enterprise_linux enterprise_linux_desktop openbsd linux ubuntu_linux linux_advanced_workstation mandrake_linux mandrake_linux_corporate_server fedora_core slackware_linux +4 more products- Published: Apr. 06, 2007
- Modified: Apr. 09, 2025
-
3.8
LOWCVE-2019-2501
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to t... Read more
Affected Products : vm_virtualbox- Published: Jan. 16, 2019
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2020-11947
iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process memory to an attacker.... Read more
Affected Products : qemu- Published: Dec. 31, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2020-16128
The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.... Read more
Affected Products : ubuntu_linux- Published: Dec. 09, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2022-2307
A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Acces... Read more
Affected Products : gitlab- Published: Aug. 05, 2022
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2023-42235
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple parameters of /monitor/s_normalizedtrans.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42236
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /common/ajaxfunction.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42238
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_eps.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42240
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /monitor/s_scheduledfile.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42242
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /monitor/s_terminal.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2024-55592
An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions, 6.1 all versions, 5.4 all ver... Read more
Affected Products : fortisiem- Published: Mar. 11, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authorization
-
3.8
LOWCVE-2024-29948
There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulnerability by sending specially crafted messages to a vulnerable device, causing a service abnormality.... Read more
Affected Products :- Published: Apr. 02, 2024
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-29196
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. There is a Path Traversal vulnerability in Attachments that allows attackers with admin rights to upload malicious files to other locations of the web r... Read more
Affected Products : phpmyfaq- Published: Mar. 26, 2024
- Modified: Jan. 09, 2025
-
3.8
LOWCVE-2024-34218
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter.... Read more
- Published: May. 14, 2024
- Modified: Apr. 04, 2025
-
3.8
LOWCVE-2023-42419
Maintenance Server, in Cybellum's QCOW air-gapped distribution (China Edition), versions 2.15.5 through 2.27, was compiled with a hard-coded private cryptographic key. An attacker with administrative privileges & access to the air-gapped server could po... Read more
Affected Products :- Published: Mar. 05, 2024
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2023-38420
Improper conditions check in Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable information disclosure via local access.... Read more
- Published: May. 16, 2024
- Modified: Sep. 02, 2025
-
3.8
LOWCVE-2018-20927
cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024