Latest CVE Feed
-
3.7
LOWCVE-2012-3128
Unspecified vulnerability in Oracle SPARC T-Series Servers running System Firmware 8.2.0 and 8.1.4.e or earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Integrated Lights Out Manager.... Read more
Affected Products : netra_sparc_t3-1 sparc_t3-1 sparc_t3-1b sparc_t3-4 netra_sparc_t3-1b sparc_t3-2 sparc_t4-1 sparc_t4-1b sparc_t4-2 sparc_t4-4 +4 more products- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2000-1096
crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is owned by the user executing the crontab -e command, which allows local users with write access to the crontab spool directory to execute a... Read more
Affected Products : vixie_cron- Published: Jan. 09, 2001
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2004-1683
A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the PATH environment variable to reference a malicious io-graphics program before is executed by crrtrap.... Read more
Affected Products : rtos- Published: Sep. 13, 2004
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2001-1085
Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.... Read more
Affected Products : lmail- Published: Jul. 05, 2001
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2023-48711
google-translate-api-browser is an npm package which interfaces with the google translate web api. A Server-Side Request Forgery (SSRF) Vulnerability is present in applications utilizing the `google-translate-api-browser` package and exposing the `transla... Read more
Affected Products : google_translate_api_browser- Published: Nov. 24, 2023
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2022-39231
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions prior to 4.10.16, or from 5.0.0 to 5.2.6, validation of the authentication adapter app ID for _Facebook_ and _Spotify_ may be circumvented.... Read more
Affected Products : parse-server- Published: Sep. 23, 2022
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2004-2626
GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SMS messages by overlaying a confirmation message with a malicious message.... Read more
Affected Products : s55- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2023-47818
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in LWS LWS Hide Login allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LWS Hide Login: from n/a through 2.1.8.... Read more
Affected Products : lws_hide_login- Published: Jun. 04, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-30132
HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors.... Read more
Affected Products : nomad_server_on_domino- Published: Oct. 01, 2024
- Modified: Oct. 29, 2024
-
3.7
LOWCVE-2023-0785
A vulnerability classified as problematic was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file check_availability.php. The manipulation of the argument username leads to exposure o... Read more
- Published: Feb. 12, 2023
- Modified: Mar. 07, 2025
-
3.7
LOWCVE-2024-30480
Authentication Bypass by Spoofing vulnerability in Pippin Williamson CGC Maintenance Mode allows Functionality Bypass.This issue affects CGC Maintenance Mode: from n/a through 1.2.... Read more
Affected Products :- Published: May. 17, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-0347
A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file signup_teacher.php. The manipulation of the argument Password leads to weak password requirements... Read more
Affected Products : engineers_online_portal- Published: Jan. 09, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2022-2583
A race condition can cause incorrect HTTP request routing.... Read more
Affected Products : gobase- Published: Dec. 27, 2022
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2023-30857
@aedart/support is the support package for Ion, a monorepo for JavaScript/TypeScript packages. Prior to version `0.6.1`, there is a possible prototype pollution issue for the `MetadataRecord`, when merged with a base class' metadata object, in `meta` deco... Read more
Affected Products : ion- Published: Apr. 28, 2023
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2022-45433
Some Dahua software products have a vulnerability of unauthenticated traceroute host from remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could get the tr... Read more
- Published: Dec. 27, 2022
- Modified: Apr. 14, 2025
-
3.7
LOWCVE-2024-35232
github.com/huandu/facebook is a Go package that fully supports the Facebook Graph API with file upload, batch request and marketing API. access_token can be exposed in error message on fail in HTTP request. This issue has been patched in version 2.7.2. ... Read more
Affected Products :- Published: May. 24, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-9654
The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient validation checks within the 'verify_guest_email' function to ensure the requesting user is the inte... Read more
Affected Products : easy_digital_downloads- Published: Dec. 17, 2024
- Modified: Feb. 07, 2025
-
3.7
LOWCVE-2005-1039
Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files.... Read more
Affected Products : coreutils- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2014-2459
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.3.2 and 6.3.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Security.... Read more
Affected Products : supply_chain_products_suite- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
3.7
LOWCVE-2023-6467
A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as problematic. This issue affects some unknown processing of the file /Websquare/likeClickComment/ of the component Comment Like Handler. The manipulation leads to improper enforcement ... Read more
Affected Products : icecms- Published: Dec. 02, 2023
- Modified: Nov. 21, 2024