Latest CVE Feed
-
3.7
LOWCVE-2024-40632
Linkerd is an open source, ultralight, security-first service mesh for Kubernetes. In affected versions when the application being run by linkerd is susceptible to SSRF, an attacker could potentially trigger a denial-of-service (DoS) attack by making requ... Read more
Affected Products :- Published: Jul. 15, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2012-3128
Unspecified vulnerability in Oracle SPARC T-Series Servers running System Firmware 8.2.0 and 8.1.4.e or earlier allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Integrated Lights Out Manager.... Read more
Affected Products : netra_sparc_t3-1 sparc_t3-1 sparc_t3-1b sparc_t3-4 netra_sparc_t3-1b sparc_t3-2 sparc_t4-1 sparc_t4-1b sparc_t4-2 sparc_t4-4 +4 more products- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2006-2452
GNOME GDM 2.8, 2.12, 2.14, and 2.15, when the "face browser" feature is enabled, allows local users to access the "Configure Login Manager" functionality using their own password instead of the root password, which can be leveraged to gain additional priv... Read more
Affected Products : gdm- Published: Jun. 09, 2006
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2008-1142
rxvt 2.6.4 opens a terminal window on :0 if the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: it was later reported that rxvt-unicode, mrxvt, aterm, multi-aterm, and wterm are also affected. NOTE... Read more
- Published: Apr. 07, 2008
- Modified: Apr. 09, 2025
-
3.7
LOWCVE-2022-45430
Some Dahua software products have a vulnerability of unauthenticated enable or disable SSHD service. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could enable or disable ... Read more
- Published: Dec. 27, 2022
- Modified: Apr. 11, 2025
-
3.7
LOWCVE-2023-36325
i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 and IPv6 addresses that occurs when a tunneled, replayed message has a behavior discrepancy (it... Read more
Affected Products :- Published: Oct. 09, 2024
- Modified: Nov. 04, 2024
-
3.7
LOWCVE-2021-2448
Vulnerability in the Oracle Financial Services Crime and Compliance Investigation Hub product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 20.1.2. Difficult to exploit vulnerability allows high ... Read more
Affected Products : financial_services_crime_and_compliance_investigation_hub- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2021-43980
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18... Read more
- Published: Sep. 28, 2022
- Modified: May. 21, 2025
-
3.7
LOWCVE-2025-29923
go-redis is the official Redis client library for the Go programming language. Prior to 9.5.5, 9.6.3, and 9.7.3, go-redis potentially responds out of order when `CLIENT SETINFO` times out during connection establishment. This can happen when the client is... Read more
Affected Products :- Published: Mar. 20, 2025
- Modified: Mar. 20, 2025
- Vuln Type: Race Condition
-
3.7
LOWCVE-2025-32471
The device’s passwords have not been adequately salted, making them vulnerable to password extraction attacks.... Read more
Affected Products :- Published: Apr. 28, 2025
- Modified: Apr. 29, 2025
- Vuln Type: Cryptography
-
3.7
LOWCVE-2024-25616
Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in the IKE_AUTH negotiation process. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depe... Read more
Affected Products : arubaos- Published: Mar. 05, 2024
- Modified: Jul. 28, 2025
-
3.7
LOWCVE-2020-26229
TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and before version 10.4.10, RSS widgets are susceptible to XML external entity processing. This vulnerability is reasonable, but is theoretical - it was not pos... Read more
Affected Products : typo3- Published: Nov. 23, 2020
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2023-32251
A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed through the use of async... Read more
Affected Products : linux_kernel- Published: Jul. 31, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Authentication
-
3.7
LOWCVE-2024-30119
HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during redirection.... Read more
Affected Products :- Published: Jun. 14, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2023-49559
An issue in vektah gqlparser open-source-library v.2.5.10 allows a remote attacker to cause a denial of service via a crafted script to the parserDirectives function.... Read more
Affected Products :- Published: Jun. 12, 2024
- Modified: Dec. 03, 2024
-
3.7
LOWCVE-2004-2626
GUI overlay vulnerability in the Java API in Siemens S55 cellular phones allows remote attackers to send unauthorized SMS messages by overlaying a confirmation message with a malicious message.... Read more
Affected Products : s55- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2023-47818
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in LWS LWS Hide Login allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LWS Hide Login: from n/a through 2.1.8.... Read more
Affected Products : lws_hide_login- Published: Jun. 04, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2023-48335
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Webcraftic Hide login page allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Hide login page: from n/a through 1.1.9.... Read more
Affected Products :- Published: Jun. 04, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2023-27437
Missing Authorization vulnerability in Event Espresso Event Espresso 4 Decaf allows Functionality Misuse.This issue affects Event Espresso 4 Decaf: from n/a through 4.10.44.Decaf.... Read more
Affected Products :- Published: Jun. 03, 2024
- Modified: Nov. 21, 2024
-
3.7
LOWCVE-2024-22139
Authentication Bypass by Spoofing vulnerability in Filipe Seabra WordPress Manutenção allows Functionality Bypass.This issue affects WordPress Manutenção: from n/a through 1.0.6.... Read more
Affected Products :- Published: May. 17, 2024
- Modified: Nov. 21, 2024