Latest CVE Feed
-
3.8
LOWCVE-2025-5715
A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentication Handler. The manipulation leads to missing critical step in authentication. I... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authentication
-
3.8
LOWCVE-2024-13116
The Crelly Slider WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (... Read more
Affected Products : crelly_slider- Published: Jan. 27, 2025
- Modified: May. 13, 2025
- Vuln Type: Cross-Site Scripting
-
3.8
LOWCVE-2020-16128
The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.... Read more
Affected Products : ubuntu_linux- Published: Dec. 09, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2023-42242
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /monitor/s_terminal.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42236
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /common/ajaxfunction.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42240
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /monitor/s_scheduledfile.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42235
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple parameters of /monitor/s_normalizedtrans.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2023-42238
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_eps.php.... Read more
Affected Products : visual_access_manager- Published: Jan. 13, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Injection
-
3.8
LOWCVE-2018-20927
cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382).... Read more
Affected Products : cpanel- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2023-2434
The Nested Pages plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'reset' function in versions up to, and including, 3.2.3. This makes it possible for authenticated attackers, with editor-level permi... Read more
Affected Products : nested_pages- Published: May. 31, 2023
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2025-47938
TYPO3 is an open source, PHP based web content management system. Starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS, the backend user management interface allows password changes without ... Read more
Affected Products : typo3- Published: May. 20, 2025
- Modified: Sep. 03, 2025
- Vuln Type: Authentication
-
3.8
LOWCVE-2020-12829
In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback. A local attacker could abuse this f... Read more
- Published: Aug. 31, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2021-3595
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issu... Read more
- Published: Jun. 15, 2021
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2015-2651
Unspecified vulnerability in Oracle Sun Solaris 11.2 allows local users to affect availability via vectors related to Kernel Zones virtualized NIC driver.... Read more
Affected Products : solaris- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
3.8
LOWCVE-2020-6197
SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download the portables.... Read more
Affected Products : enable_now- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-29196
phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. There is a Path Traversal vulnerability in Attachments that allows attackers with admin rights to upload malicious files to other locations of the web r... Read more
Affected Products : phpmyfaq- Published: Mar. 26, 2024
- Modified: Jan. 09, 2025
-
3.8
LOWCVE-2016-3158
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by lever... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
3.8
LOWCVE-2020-3951
VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) contain a denial-of-service vulnerability due to a heap-overflow issue in Cortado Thinprint. Attackers with non-administrative access to a guest VM with vi... Read more
- Published: Mar. 17, 2020
- Modified: Nov. 21, 2024
-
3.8
LOWCVE-2024-6219
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.... Read more
Affected Products : lxd- Published: Dec. 06, 2024
- Modified: Aug. 28, 2025
-
3.8
LOWCVE-2025-6942
The distributed engine versions 8.4.39.0 and earlier of Secret Server versions 11.7.49 and earlier can be exploited during an initial authorization event that would allow an attacker to impersonate another distributed engine.... Read more
Affected Products : secret_server- Published: Jul. 02, 2025
- Modified: Jul. 03, 2025
- Vuln Type: Authentication