Latest CVE Feed
-
3.7
LOWCVE-2025-51586
An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.... Read more
Affected Products : prestashop- Published: Sep. 08, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Information Disclosure
-
3.7
LOWCVE-2024-25616
Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depe... Read more
Affected Products : arubaos- Published: Mar. 05, 2024
- Modified: Jul. 28, 2025
-
3.7
LOWCVE-2023-34401
Mercedes-Benz head-unit NTG6 contains functions to import or export profile settings over USB. Inside profile folder there is a file, which is encoded with proprietary UD2 codec. Due to missed size checks in the enapsulate file, attacker can achieve Out-o... Read more
Affected Products : headunit_ntg6_mercedes-benz_user_experience- Published: Feb. 13, 2025
- Modified: Jun. 27, 2025
- Vuln Type: Memory Corruption
-
3.7
LOWCVE-2023-41306
Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this vulnerability may cause the bone voice ID feature to be unavailable.... Read more
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2022-41914
Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM) account management enabled, Zulip Server 5.0 through 5.6 checked the SCIM bearer token using a comparator that did not run in constan... Read more
- Published: Nov. 16, 2022
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2023-49741
Authentication Bypass by Spoofing vulnerability in wpdevart Coming soon and Maintenance mode allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming soon and Maintenance mode: from n/a through 3.7.3.... Read more
Affected Products :- Published: Jun. 04, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-31265
Cross-Site Request Forgery (CSRF) vulnerability in SumoMe Sumo.This issue affects Sumo: from n/a through 1.34. ... Read more
Affected Products :- Published: Apr. 12, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-30110
HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into a system which can cause the system to behave in unexpected ways.... Read more
Affected Products :- Published: Jun. 28, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-3689
A vulnerability classified as problematic has been found in Zhejiang Land Zongheng Network Technology O2OA up to 20240403. Affected is an unknown function of the file /x_portal_assemble_surface/jaxrs/portal/list?v=8.2.3-4-43f4fe3. The manipulation leads t... Read more
Affected Products :- Published: Apr. 12, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-30109
HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layers to trick a user into clicking on a button or link on another page than the one intended.... Read more
Affected Products :- Published: Jun. 28, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-39302
BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file permissions in the `/usr/local/bigbluebutton/core/vendor/bundle/ruby/2.7.0/gems/resque-2.6.0`... Read more
Affected Products : bigbluebutton- Published: Jun. 28, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2023-47769
Authentication Bypass by Spoofing vulnerability in WP Maintenance allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Maintenance: from n/a through 6.1.3.... Read more
Affected Products : wp_maintenance- Published: Jun. 04, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2000-0409
Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.... Read more
Affected Products : communicator- Published: May. 10, 2000
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2023-49822
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Vongries Ultimate Dashboard allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Ultimate Dashboard: from n/a through 3.7.10.... Read more
Affected Products :- Published: Jun. 04, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2023-48711
google-translate-api-browser is an npm package which interfaces with the google translate web api. A Server-Side Request Forgery (SSRF) Vulnerability is present in applications utilizing the `google-translate-api-browser` package and exposing the `transla... Read more
Affected Products : google_translate_api_browser- Published: Nov. 24, 2023
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2010-0014
System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, via an arbitrary password, to the screen-locking program on a workstation tha... Read more
Affected Products : sssd- Published: Jan. 14, 2010
- Modified: Apr. 09, 2025
-
3.7
LOWCVE-2024-21208
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4, 23; Or... Read more
- Published: Oct. 15, 2024
- Modified: Jun. 18, 2025
-
3.7
LOWCVE-2016-0688
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via vectors related to Core Components.... Read more
Affected Products : weblogic_server- Published: Apr. 21, 2016
- Modified: Apr. 12, 2025
-
3.7
LOWCVE-2023-0785
A vulnerability classified as problematic was found in SourceCodester Best Online News Portal 1.0. Affected by this vulnerability is an unknown functionality of the file check_availability.php. The manipulation of the argument username leads to exposure o... Read more
- Published: Feb. 12, 2023
- Modified: Mar. 07, 2025
-
3.7
LOWCVE-2023-28322
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the s... Read more
Affected Products : fedora curl macos h300s_firmware h500s_firmware h700s_firmware h410s_firmware clustered_data_ontap ontap_antivirus_connector h300s +3 more products- Published: May. 26, 2023
- Modified: Nov. 21, 2024