Latest CVE Feed
-
3.7
LOWCVE-2021-42948
HotelDruid Hotel Management Software v3.0.3 and below was discovered to have exposed session tokens in multiple links via GET parameters, allowing attackers to access user session id's.... Read more
Affected Products : hoteldruid- Published: Sep. 16, 2022
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2011-0839
Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows local users to affect availability, related to LOFS.... Read more
- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-1999-0123
Race condition in Linux mailx command allows local users to read user files.... Read more
Affected Products : slackware_linux- Published: Dec. 01, 1995
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2016-9015
Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-m... Read more
Affected Products : urllib3- Published: Jan. 11, 2017
- Modified: Apr. 20, 2025
-
3.7
LOWCVE-2024-9506
Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability.... Read more
Affected Products :- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
3.7
LOWCVE-1999-0401
A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.... Read more
Affected Products : linux_kernel- Published: Jan. 01, 1999
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-1999-0141
Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.... Read more
Affected Products : navigator- Published: Mar. 29, 1996
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2008-1696
Directory traversal vulnerability in makepost.php in DaZPHPNews 0.1-1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the prefixdir parameter.... Read more
Affected Products : dazphpnews- Published: Apr. 08, 2008
- Modified: Apr. 09, 2025
-
3.7
LOWCVE-2025-51586
An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.... Read more
Affected Products : prestashop- Published: Sep. 08, 2025
- Modified: Sep. 12, 2025
- Vuln Type: Information Disclosure
-
3.7
LOWCVE-2005-2306
Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate authentication token to multiple sessions, which could allow authenticated users to gain privileges as other users.... Read more
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2023-41306
Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this vulnerability may cause the bone voice ID feature to be unavailable.... Read more
- Published: Sep. 27, 2023
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-22403
Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an authorization code they could authenticate at any time using the code. As of version 28.0.0 OAuth codes are i... Read more
- Published: Jan. 18, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2012-0105
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization 4.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Windows Guest Additions.... Read more
- Published: Jan. 18, 2012
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2012-5659
Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment v... Read more
Affected Products : automatic_bug_reporting_tool- Published: Mar. 12, 2013
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2013-0219
System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.... Read more
- Published: Feb. 24, 2013
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2023-49748
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPServeur, NicolasKulka, wpformation WPS Hide Login allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPS Hide Login: from n/a through 1.9.11.... Read more
Affected Products :- Published: Jun. 04, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2004-1445
A race condition in nessus-adduser in Nessus 2.0.11 and possibly earlier versions, if the TMPDIR environment variable is not set, allows local users to gain privileges.... Read more
Affected Products : nessus- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2001-0317
Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process.... Read more
Affected Products : linux_kernel- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2005-1768
Race condition in the ia32 compatibility code for the execve system call in Linux kernel 2.4 before 2.4.31 and 2.6 before 2.6.6 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a concurrent thread that... Read more
Affected Products : linux_kernel- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2023-38546
This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application creates "easy handles" that are the individual handles for s... Read more
- Published: Oct. 18, 2023
- Modified: Feb. 13, 2025