Latest CVE Feed
-
3.8
LOWCVE-2024-0173
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.... Read more
- Published: Mar. 13, 2024
- Modified: Jan. 31, 2025
-
3.8
LOWCVE-2023-21889
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.42 and prior to 7.0.6. Easily exploitable vulnerability allows low privileged attacker with logon to the ... Read more
Affected Products : vm_virtualbox- Published: Jan. 18, 2023
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-25351
SQL Injection vulnerability in /zms/admin/changeimage.php in PHPGurukul Zoo Management System 1.0 allows attackers to run arbitrary SQL commands via the editid parameter.... Read more
Affected Products : zoo_management_system- Published: Feb. 28, 2024
- Modified: Mar. 27, 2025
-
3.8
LOWCVE-2010-2393
Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect availability, related to RPC.... Read more
- Published: Jul. 13, 2010
- Modified: Apr. 11, 2025
-
3.8
LOWCVE-2017-18384
cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2023-29128
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connect 7 CC716 (All versions >= V2.0 < V2.1). The filename in the upload feature of the web based management of the affected device is susce... Read more
- Published: May. 09, 2023
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-56321
GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potentially execute arbitrary scripts on the hosting server or container as GoCD's... Read more
Affected Products : gocd- Published: Jan. 03, 2025
- Modified: Aug. 01, 2025
-
3.8
LOWCVE-2020-26625
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the 'user_id' parameter after the login portal.... Read more
Affected Products : gila_cms- Published: Jan. 02, 2024
- Modified: May. 16, 2025
-
3.8
LOWCVE-2025-58827
Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager allows Code Injection. This issue affects Job Board Manager: from n/a through 2.1.61.... Read more
Affected Products :- Published: Sep. 05, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2025-46094
LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript.... Read more
Affected Products : liquidfiles- Published: Aug. 04, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Path Traversal
-
3.8
LOWCVE-2024-13308
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Scripting (XSS).This issue affects Browser Back Button: from 1.0.0 before 2.0.2.... Read more
- Published: Jan. 09, 2025
- Modified: Sep. 05, 2025
- Vuln Type: Cross-Site Scripting
-
3.8
LOWCVE-2018-15532
SynTP.sys in Synaptics Touchpad drivers before 2018-06-06 allows local users to obtain sensitive information about freed kernel addresses.... Read more
Affected Products : synaptics_touchpad_driver- Published: Mar. 21, 2019
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2020-26624
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.... Read more
Affected Products : gila_cms- Published: Jan. 02, 2024
- Modified: Jun. 17, 2025
-
3.8
LOWCVE-2017-4896
Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthorized disclosure of confidential data.... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
3.8
LOWCVE-2020-26623
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.... Read more
Affected Products : gila_cms- Published: Jan. 02, 2024
- Modified: Jun. 03, 2025
-
3.8
LOWCVE-2025-0914
An improper access control issue in the VQL shell feature in Velociraptor Versions < 0.73.4 allowed authenticated users to execute the execve() plugin in deployments where this was explicitly forbidden by configuring the prevent_execve flag in the configu... Read more
Affected Products : velociraptor- Published: Feb. 27, 2025
- Modified: Feb. 27, 2025
- Vuln Type: Authorization
-
3.8
LOWCVE-2024-5445
Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor to perform a Man-in-the-Middle and intercept traffic between the agent and N-able servers... Read more
Affected Products :- Published: Aug. 12, 2024
- Modified: Jan. 07, 2025
-
3.8
LOWCVE-2024-34218
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter.... Read more
- Published: May. 14, 2024
- Modified: Apr. 04, 2025
-
3.8
LOWCVE-2025-24388
A vulnerability in the OTRS Admin Interface and Agent Interface (versions before OTRS 8) allow parameter injection due to for an autheniticated agent or admin user. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X ... Read more
Affected Products : otrs- Published: Jun. 16, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2024-3628
The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed... Read more
Affected Products : easyevent- Published: May. 07, 2024
- Modified: May. 09, 2025