Latest CVE Feed
-
3.7
LOWCVE-2025-54787
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM version 7.14.6 which allows unauthenticated downloads of any file from the upload-directory, as long as it is na... Read more
Affected Products : suitecrm- Published: Aug. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
3.7
LOWCVE-2010-0014
System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, via an arbitrary password, to the screen-locking program on a workstation tha... Read more
Affected Products : sssd- Published: Jan. 14, 2010
- Modified: Apr. 09, 2025
-
3.7
LOWCVE-2024-21210
Vulnerability in Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4 and 23. Difficult to exploit vulnerability allows unauthenticated attacker with network access via... Read more
- Published: Oct. 15, 2024
- Modified: Jun. 18, 2025
-
3.7
LOWCVE-2021-41136
Puma is a HTTP 1.1 server for Ruby/Rack applications. Prior to versions 5.5.1 and 4.3.9, using `puma` with a proxy which forwards HTTP header values which contain the LF character could allow HTTP request smugggling. A client could smuggle a request throu... Read more
- Published: Oct. 12, 2021
- Modified: May. 27, 2025
-
3.7
LOWCVE-2015-7408
The server in IBM Spectrum Protect (aka Tivoli Storage Manager) 5.5 and 6.x before 6.3.5.1 and 7.x before 7.1.4 does not properly restrict use of the ASNODENAME option, which allows remote attackers to read or write to backup data by leveraging proxy auth... Read more
Affected Products : tivoli_storage_manager- Published: Feb. 15, 2016
- Modified: Apr. 12, 2025
-
3.7
LOWCVE-2015-4834
Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Utility/Zones.... Read more
Affected Products : solaris- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
3.7
LOWCVE-2007-0235
Stack-based buffer overflow in the glibtop_get_proc_map_s function in libgtop before 2.14.6 (libgtop2) allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a process with a long filename that is mapped in its add... Read more
Affected Products : libgtop- Published: Jan. 16, 2007
- Modified: Apr. 09, 2025
-
3.7
LOWCVE-2022-35252
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to a... Read more
Affected Products : debian_linux curl hci_management_node solidfire macos element_software h300s_firmware h500s_firmware h700s_firmware h410s_firmware +8 more products- Published: Sep. 23, 2022
- Modified: May. 05, 2025
-
3.7
LOWCVE-2022-31679
Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP reque... Read more
Affected Products : spring_data_rest- Published: Sep. 21, 2022
- Modified: May. 22, 2025
-
3.7
LOWCVE-2022-23292
Microsoft Power BI Spoofing Vulnerability... Read more
Affected Products : on-premises_data_gateway- Published: Apr. 15, 2022
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-42332
The researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with additional lines of information and have forged data show in the Zabbix UI. This attack requires SNMP auth to be off and/or the attacker to ... Read more
Affected Products : zabbix- Published: Nov. 27, 2024
- Modified: Nov. 27, 2024
-
3.7
LOWCVE-2005-1993
Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack.... Read more
Affected Products : sudo- Published: Jun. 20, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2012-0787
The clone_file function in transfer.c in Augeas before 1.0.0, when copy_if_rename_fails is set and EXDEV or EBUSY is returned by the rename function, allows local users to overwrite arbitrary files and obtain sensitive information via a bind mount on the ... Read more
- Published: Nov. 23, 2013
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2023-23985
Missing Authorization vulnerability in Quiz Maker team Quiz Maker.This issue affects Quiz Maker: from n/a through 6.3.9.4. ... Read more
Affected Products : quiz_maker- Published: Apr. 24, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2023-33855
Under certain conditions, RSA operations performed by IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 may exhibit non-constant-time behavior. This could allow a remote attacker to obtain sensitive information using a timing-based attack.... Read more
- Published: Mar. 26, 2024
- Modified: Jul. 25, 2025
-
3.7
LOWCVE-2005-0953
Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.... Read more
Affected Products : bzip2- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2024-4596
A vulnerability was found in Kimai up to 2.15.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Session Handler. The manipulation of the argument PHPSESSIONID leads to information disclosure. The attack... Read more
Affected Products : kimai- Published: May. 07, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2006-2452
GNOME GDM 2.8, 2.12, 2.14, and 2.15, when the "face browser" feature is enabled, allows local users to access the "Configure Login Manager" functionality using their own password instead of the root password, which can be leveraged to gain additional priv... Read more
Affected Products : gdm- Published: Jun. 09, 2006
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2024-30130
HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information.... Read more
Affected Products : nomad_server_on_domino- Published: Jul. 19, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2005-1039
Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files.... Read more
Affected Products : coreutils- Published: May. 02, 2005
- Modified: Apr. 03, 2025