Latest CVE Feed
-
2.3
LOWCVE-2024-40594
The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a location accessible to other apps.... Read more
Affected Products :- Published: Jul. 06, 2024
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2022-20240
In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not... Read more
Affected Products : android- EPSS Score: %0.00
- Published: Dec. 13, 2022
- Modified: Apr. 22, 2025
-
2.3
LOWCVE-2024-34715
Fides is an open-source privacy engineering platform. The Fides webserver requires a connection to a hosted PostgreSQL database for persistent storage of application data. If the password used by the webserver for this database connection includes special... Read more
Affected Products : fides- Published: May. 29, 2024
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2022-20543
In multiple locations, there is a possible display crash loop due to improper input validation. This could lead to local denial of service with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: A... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Dec. 16, 2022
- Modified: Apr. 21, 2025
-
2.3
LOWCVE-2022-31223
Dell BIOS versions contain an Improper Neutralization of Null Byte vulnerability. A local authenticated administrator user could potentially exploit this vulnerability by sending unexpected null bytes in order to read memory on the system.... Read more
- EPSS Score: %0.04
- Published: Sep. 12, 2022
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2024-48866
An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to run the system into unexpected state. We have already fi... Read more
- Published: Dec. 06, 2024
- Modified: Dec. 06, 2024
-
2.3
LOWCVE-2017-8118
The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.... Read more
Affected Products : uma- EPSS Score: %0.03
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
2.3
LOWCVE-2018-20893
cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).... Read more
Affected Products : cpanel- EPSS Score: %0.08
- Published: Aug. 01, 2019
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2018-2923
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: Core Services). The supported version that is affected is Prior to 8.7.20. Easily exploitable vulnerability allows high privileged attack... Read more
- EPSS Score: %0.09
- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2021-34397
Bootloader contains a vulnerability in NVIDIA MB2, which may cause free-the-wrong-heap, which may lead to limited denial of service.... Read more
- EPSS Score: %0.06
- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2022-20261
In LocationManager, there is a possible way to get location information due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: An... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Aug. 12, 2022
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2022-29812
In JetBrains IntelliJ IDEA before 2022.1 notification mechanisms about using Unicode directionality formatting characters were insufficient... Read more
Affected Products : intellij_idea- EPSS Score: %0.00
- Published: Apr. 28, 2022
- Modified: Nov. 21, 2024
-
2.2
LOWCVE-2023-23349
Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker mu... Read more
Affected Products :- Published: Mar. 22, 2024
- Modified: Nov. 21, 2024
-
2.2
LOWCVE-2024-53861
pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`. This is a bug introduced in version 2.10.0: checking the "iss" claim changed from `isinstance(... Read more
Affected Products : pyjwt- Published: Nov. 29, 2024
- Modified: Dec. 02, 2024
-
2.2
LOWCVE-2024-51755
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the `__isset()` method is now called after the sec... Read more
Affected Products : twig- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
2.2
LOWCVE-2025-29991
Yubico YubiKey 5.4.1 through 5.7.3 before 5.7.4 has an incorrect FIDO CTAP PIN/UV Auth Protocol Two implementation. It uses the signature length from CTAP PIN/UV Auth Protocol One, even when CTAP PIN/UV Auth Protocol Two was chosen, resulting in a partial... Read more
Affected Products :- Published: Apr. 03, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Authentication
-
2.2
LOWCVE-2024-21101
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.33 and prior, 7.6.29 and prior, 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows high p... Read more
- Published: Apr. 16, 2024
- Modified: Feb. 10, 2025
-
2.2
LOWCVE-2024-21237
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileg... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
2.2
LOWCVE-2024-4811
In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.... Read more
- Published: Jul. 25, 2024
- Modified: Jul. 02, 2025
-
2.2
LOWCVE-2024-53564
A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what... Read more
Affected Products : freepbx- Published: Dec. 02, 2024
- Modified: Jan. 09, 2025