Latest CVE Feed
-
3.8
LOWCVE-2020-3970
VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds read vulnerability in the Shader functionali... Read more
- Published: Jun. 25, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2020-11947
iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process memory to an attacker.... Read more
Affected Products : qemu- Published: Dec. 31, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2023-4304
Business Logic Errors in GitHub repository froxlor/froxlor prior to 2.0.22,2.1.0. ... Read more
Affected Products : froxlor- Published: Aug. 11, 2023
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-45599
Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, any program that is run on the machine is able to access the camera or the microphone without explicitly b... Read more
Affected Products : cursor- Published: Sep. 25, 2024
- Modified: Sep. 26, 2024
-
3.8
LOWCVE-2024-39324
aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a editors to manage own services via GraphQL API which isn't allowed... Read more
Affected Products : ai-admin-graphql- Published: Jul. 02, 2024
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-53502
Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.... Read more
Affected Products : semcms- Published: Dec. 03, 2024
- Modified: Apr. 04, 2025
-
3.8
LOWCVE-2019-0162
Memory access in virtual memory mapping for some microprocessors may allow an authenticated user to potentially enable information disclosure via local access.... Read more
Affected Products : -- Published: Apr. 17, 2019
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2023-23814
Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar : from n/a through 1.4.13.... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
3.8
LOWCVE-2025-32971
XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the Solr script service doesn't take dropped programming rights into account. The Solr scr... Read more
Affected Products : xwiki- Published: Apr. 30, 2025
- Modified: May. 13, 2025
- Vuln Type: Misconfiguration
-
3.8
LOWCVE-2022-22450
IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916.... Read more
- Published: Jul. 14, 2022
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2025-25877
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /admin.php. The attack can use SQL injection to obtain sensitive data.... Read more
Affected Products : simple_chatbox- Published: Feb. 21, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2020-26623
SQL Injection vulnerability discovered in Gila CMS 1.15.4 and earlier allows a remote attacker to execute arbitrary web scripts via the Area parameter under the Administration>Widget tab after the login portal.... Read more
Affected Products : gila_cms- Published: Jan. 02, 2024
- Modified: Jun. 03, 2025
-
3.8
LOWCVE-2020-26624
A SQL injection vulnerability was discovered in Gila CMS 1.15.4 and earlier which allows a remote attacker to execute arbitrary web scripts via the ID parameter after the login portal.... Read more
Affected Products : gila_cms- Published: Jan. 02, 2024
- Modified: Jun. 17, 2025
-
3.8
LOWCVE-2017-4896
Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthorized disclosure of confidential data.... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
3.8
LOWCVE-2024-34203
TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setLanguageCfg function.... Read more
- Published: May. 14, 2024
- Modified: Apr. 03, 2025
-
3.8
LOWCVE-2024-30142
HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthorized access or session cookies could be transferred over an unencrypted channel.... Read more
Affected Products : bigfix_compliance- Published: Nov. 07, 2024
- Modified: Jun. 17, 2025
-
3.8
LOWCVE-2017-18384
cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).... Read more
Affected Products : cpanel- Published: Aug. 02, 2019
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-35039
idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/tplSys_deal.php?mudi=area.... Read more
- Published: May. 16, 2024
- Modified: Apr. 15, 2025
-
3.8
LOWCVE-2022-24886
Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. In versions prior to 3.19.0, any application with notification permission can access contacts if Nextcloud has access to Contacts without applying for the Cont... Read more
- Published: Apr. 27, 2022
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-8612
A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete could be larger than the true size of the data which... Read more
Affected Products :- Published: Sep. 20, 2024
- Modified: Nov. 21, 2024