Latest CVE Feed
-
2.8
LOWCVE-2016-4511
ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local users to obtain sensitive cleartext information by leveraging read access to the ACTConfig configuration file.... Read more
Affected Products : pcm600- EPSS Score: %0.05
- Published: Jun. 10, 2016
- Modified: Apr. 12, 2025
-
2.8
LOWCVE-2024-22194
cdo-local-uuid project provides a specialized UUID-generating function that can, on user request, cause a program to generate deterministic UUIDs. An information leakage vulnerability is present in `cdo-local-uuid` at version `0.4.0`, and in `case-utils` ... Read more
- EPSS Score: %0.03
- Published: Jan. 11, 2024
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2019-3729
RSA BSAFE Micro Edition Suite versions prior to 4.4 (in 4.0.x, 4.1.x, 4.2.x and 4.3.x) are vulnerable to a Heap-based Buffer Overflow vulnerability when parsing ECDSA signature. A malicious user with adjacent network access could potentially exploit this ... Read more
- EPSS Score: %0.12
- Published: Sep. 30, 2019
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2023-48303
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and Nextcloud Enterprise Server, admins can change authentication details... Read more
- EPSS Score: %0.19
- Published: Nov. 21, 2023
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2024-52905
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitive database information to a privileged user.... Read more
- Published: Mar. 10, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Information Disclosure
-
2.7
LOWCVE-2014-4022
The alloc_domain_struct function in arch/arm/domain.c in Xen 4.4.x, when running on an ARM platform, does not properly initialize the structure containing the grant table pages for a domain, which allows local guest administrators to obtain sensitive info... Read more
Affected Products : xen- EPSS Score: %0.17
- Published: Jul. 09, 2014
- Modified: Apr. 12, 2025
-
2.7
LOWCVE-2022-41962
BigBlueButton is an open source web conferencing system. Versions prior to 2.4-rc-6, and 2.5-alpha-1 contain Incorrect Authorization for setting emoji status. A user with moderator rights can use the clear status feature to set any emoji status for other ... Read more
Affected Products : bigbluebutton- EPSS Score: %0.05
- Published: Dec. 16, 2022
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2023-2400
Improper deletion of resource in the user management feature in Devolutions Server 2023.1.8 and earlier allows an administrator to view users vaults of deleted users via database access. ... Read more
Affected Products : devolutions_server- EPSS Score: %0.10
- Published: Jun. 20, 2023
- Modified: Dec. 09, 2024
-
2.7
LOWCVE-2023-50955
IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the web server installation which could aid in further attacks against the system. IBM X-Force ID: 275777.... Read more
Affected Products : infosphere_information_server- Published: Feb. 21, 2024
- Modified: Dec. 10, 2024
-
2.7
LOWCVE-2022-40199
Directory traversal vulnerability in EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p4 ) and EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote authenticated attacker with an administrative privilege to obtain the product's directory structure informati... Read more
Affected Products : ec-cube- EPSS Score: %0.44
- Published: Sep. 27, 2022
- Modified: May. 21, 2025
-
2.7
LOWCVE-2024-31450
Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. The Owncast application exposes an administrator API at the URL /api/admin. The emoji/delete endpoint of said API allows administrators to delete cust... Read more
Affected Products : owncast- Published: Apr. 19, 2024
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2024-29177
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary sensitive information vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the re... Read more
Affected Products : data_domain_operating_system- Published: Jun. 26, 2024
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2024-7038
An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user updates the model path, the system checks if the file exists and provides diff... Read more
Affected Products : open_webui- Published: Oct. 09, 2024
- Modified: Nov. 03, 2024
-
2.7
LOWCVE-2025-32205
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in piotnetdotcom Piotnet Forms. This issue affects Piotnet Forms: from n/a through 1.0.30.... Read more
Affected Products : piotnet_forms- Published: Apr. 10, 2025
- Modified: Apr. 11, 2025
- Vuln Type: Path Traversal
-
2.7
LOWCVE-2023-37833
Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary configuration edits that are only accessed by privileged users.... Read more
- EPSS Score: %0.05
- Published: Oct. 31, 2023
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2024-32882
Wagtail is an open source content management system built on Django. In affected versions if a model has been made available for editing through the `wagtail.contrib.settings` module or `ModelViewSet`, and the `permission` argument on `FieldPanel` has bee... Read more
- Published: May. 02, 2024
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2024-47577
Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for customer to manage their accounts, the request url includes customer data and it is recorded in ... Read more
Affected Products : commerce_cloud- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024
-
2.7
LOWCVE-2023-32114
SAP NetWeaver (Change and Transport System) - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, allows an authenticated user with admin privileges to maliciously run a benchmark program repeatedly in intent to slowdown or make the server una... Read more
Affected Products : netweaver- EPSS Score: %0.06
- Published: Jun. 13, 2023
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2023-48429
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI of affected devices does not check the length of parameters in certain conditions. This allows a malicious admin to crash the server by sending a crafted reque... Read more
Affected Products : sinec_ins- EPSS Score: %0.12
- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2024-32969
vantage6 is an open-source infrastructure for privacy preserving analysis. Collaboration administrators can add extra organizations to their collaboration that can extend their influence. For example, organizations that they include can then create new us... Read more
Affected Products : vantage6- Published: May. 23, 2024
- Modified: Nov. 21, 2024