Latest CVE Feed
-
2.4
LOWCVE-2020-9073
Huawei P20 smartphones with versions earlier than 10.0.0.156(C00E156R1P4) have an improper authentication vulnerability. The vulnerability is due to that when an user wants to do certain operation, the software insufficiently validate the user's identity.... Read more
- EPSS Score: %0.03
- Published: May. 15, 2020
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2024-34649
Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 05, 2024
-
2.4
LOWCVE-2024-29338
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/categories/delete/2.... Read more
Affected Products : anchor_cms- Published: Mar. 22, 2024
- Modified: Mar. 28, 2025
-
2.4
LOWCVE-2018-17177
An issue was discovered on Neato Botvac Connected 2.2.0 and Botvac 85 1.2.1 devices. Static encryption is used for the copying of so-called "black box" logs (event logs and core dumps) to a USB stick. These logs are RC4-encrypted with a 9-character passwo... Read more
- EPSS Score: %0.02
- Published: Sep. 18, 2018
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2022-36876
Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.... Read more
- EPSS Score: %0.14
- Published: Sep. 09, 2022
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2024-3629
The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : hl_twitter- Published: May. 15, 2024
- Modified: May. 15, 2025
-
2.4
LOWCVE-2021-1863
An issue existed with authenticating the action triggered by an NFC tag. The issue was addressed with improved action authentication. This issue is fixed in iOS 14.5 and iPadOS 14.5. A person with physical access to an iOS device may be able to place phon... Read more
- EPSS Score: %0.05
- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2013-0420
Unspecified vulnerability in the VirtualBox component in Oracle Virtualization 4.0, 4.1, and 4.2 allows local users to affect integrity and availability via unknown vectors related to Core. NOTE: The previous information was obtained from the January 201... Read more
- EPSS Score: %0.11
- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
2.4
LOWCVE-2024-44179
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15. An attacker with physical access to a device may be able to read contact numbers from the ... Read more
- Published: Mar. 10, 2025
- Modified: Mar. 24, 2025
- Vuln Type: Information Disclosure
-
2.4
LOWCVE-2024-12425
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation LibreOffice allows Absolute Path Traversal. An attacker can write to arbitrary locations, albeit suffixed with ".ttf", by supplying... Read more
Affected Products : libreoffice- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Path Traversal
-
2.4
LOWCVE-2024-40822
This issue was addressed by restricting options offered on a locked device. This issue is fixed in watchOS 10.6, macOS Sonoma 14.6, iOS 17.6 and iPadOS 17.6, iOS 16.7.9 and iPadOS 16.7.9. An attacker with physical access to a device may be able to access ... Read more
- Published: Jul. 29, 2024
- Modified: Mar. 27, 2025
-
2.4
LOWCVE-2024-45687
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in Payara Platform Payara Server (Grizzly, REST Management Interface modules), Payara Platform Payara Micro (Grizzly modules) allows Manipulating S... Read more
Affected Products :- Published: Jan. 21, 2025
- Modified: Jan. 21, 2025
- Vuln Type: Misconfiguration
-
2.4
LOWCVE-2025-51643
Meitrack T366G-L GPS Tracker devices contain an SPI flash chip (Winbond 25Q64JVSIQ) that is accessible without authentication or tamper protection. An attacker with physical access to the device can use a standard SPI programmer to extract the firmware us... Read more
Affected Products :- Published: Aug. 28, 2025
- Modified: Aug. 29, 2025
- Vuln Type: Information Disclosure
-
2.4
LOWCVE-2021-30918
A Lock Screen issue was addressed with improved state management. This issue is fixed in iOS 14.8.1 and iPadOS 14.8.1, iOS 15.0.1 and iPadOS 15.0.1. A user may be able to view restricted content from the Lock Screen.... Read more
- EPSS Score: %0.07
- Published: Aug. 24, 2021
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2022-22599
Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. A person with physical access to a device may be able to use Siri to obtain s... Read more
- EPSS Score: %0.11
- Published: Mar. 18, 2022
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2013-4262
svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows local users to gain privileges via a symlink attack on the pid file. NOTE: this issue was SPLIT due to different affected versions (ADT3)... Read more
Affected Products : subversion- EPSS Score: %0.34
- Published: Jul. 28, 2014
- Modified: Apr. 12, 2025
-
2.4
LOWCVE-2023-40529
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17 and iPadOS 17. A person with physical access to a device may be able to use VoiceOver to access private calendar information.... Read more
- EPSS Score: %0.12
- Published: Jan. 10, 2024
- Modified: Jun. 03, 2025
-
2.4
LOWCVE-2024-40839
This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device may be able to view notification contents from the Lock Screen.... Read more
- Published: Jan. 15, 2025
- Modified: Mar. 14, 2025
- Vuln Type: Information Disclosure
-
2.4
LOWCVE-2025-54411
Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable to XSS attacks, which affect the user themselves or an admin impersonating them. Admins can temporarily alter the welcome_banner.header.... Read more
Affected Products : discourse- Published: Aug. 19, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Cross-Site Scripting
-
2.4
LOWCVE-2023-42874
This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2. Secure text fields may be displayed via the Accessibility Keyboard when using a physical keyboard.... Read more
Affected Products : macos- EPSS Score: %0.07
- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024