Latest CVE Feed
-
2.7
LOWCVE-2022-46498
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php.... Read more
- Published: Mar. 07, 2024
- Modified: Mar. 28, 2025
-
2.7
LOWCVE-2024-3034
The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it possible for authenticated attackers, with administrator-level access and abov... Read more
Affected Products : backupwordpress- Published: Apr. 27, 2024
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2024-23600
Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information disclosure.... Read more
Affected Products :- Published: Aug. 01, 2024
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2024-30808
An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by mp42ts.... Read more
Affected Products : bento4- Published: Apr. 02, 2024
- Modified: May. 27, 2025
-
2.7
LOWCVE-2023-37833
Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits that are only accessed by privileged users.... Read more
- EPSS Score: %0.05
- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2023-50955
IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the web server installation which could aid in further attacks against the system. IBM X-Force ID: 275777.... Read more
Affected Products : infosphere_information_server- Published: Feb. 21, 2024
- Modified: Dec. 10, 2024
-
2.7
LOWCVE-2024-39353
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access to the audit logs to read message contents.... Read more
- Published: Jul. 03, 2024
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2009-3406
Unspecified vulnerability in the JD Edwards Tools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.98.2.1 allows remote authenticated users to affect confidentiality via unknown vectors.... Read more
- EPSS Score: %0.42
- Published: Oct. 22, 2009
- Modified: Apr. 09, 2025
-
2.7
LOWCVE-2024-7038
An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides diff... Read more
Affected Products : open_webui- Published: Oct. 09, 2024
- Modified: Nov. 03, 2024
-
2.7
LOWCVE-2024-32882
Wagtail is an open source content management system built on Django. In affected versions if a model has been made available for editing through the `wagtail.contrib.settings` module or `ModelViewSet`, and the `permission` argument on `FieldPanel` has bee... Read more
- Published: May. 02, 2024
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2024-29177
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary sensitive information vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the re... Read more
Affected Products : data_domain_operating_system- Published: Jun. 26, 2024
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2022-40199
Directory traversal vulnerability in EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p4 ) and EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote authenticated attacker with an administrative privilege to obtain the product's directory structure informati... Read more
Affected Products : ec-cube- EPSS Score: %0.44
- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
2.7
LOWCVE-2024-4214
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Bill Minozzi Car Dealer allows Code Injection.This issue affects Car Dealer: from n/a through 4.15.... Read more
Affected Products :- Published: May. 17, 2024
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2024-31450
Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. The Owncast application exposes an administrator API at the URL /api/admin. The emoji/delete endpoint of said API allows administrators to delete cust... Read more
Affected Products : owncast- Published: Apr. 19, 2024
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2021-0991
In OnMetadataChangedListener of AdvancedBluetoothDetailsHeaderController.java, there is a possible leak of Bluetooth MAC addresses due to log information disclosure. This could lead to local information disclosure with System execution privileges needed. ... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Dec. 15, 2021
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2022-39409
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Business Process Automation). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows high privileged attacker with ... Read more
Affected Products : transportation_management- EPSS Score: %0.10
- Published: Oct. 18, 2022
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2022-36168
A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:... Read more
Affected Products : wuzhicms- EPSS Score: %0.45
- Published: Aug. 26, 2022
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2024-41156
Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos network. Profiles can only be exported by authenticated users wit... Read more
- Published: Oct. 29, 2024
- Modified: Dec. 05, 2024
-
2.7
LOWCVE-2022-2556
The Mailchimp for WooCommerce WordPress plugin before 2.7.2 has an AJAX action that allows high privilege users to perform a POST request on behalf of the server to the internal network/LAN, the body of the request is also appended to the response so it c... Read more
Affected Products : mailchimp_for_woocommerce- EPSS Score: %0.09
- Published: Aug. 29, 2022
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2022-3710
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA.... Read more
- EPSS Score: %0.22
- Published: Dec. 01, 2022
- Modified: Apr. 23, 2025