Latest CVE Feed
-
2.4
LOWCVE-2024-3629
The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : hl_twitter- Published: May. 15, 2024
- Modified: May. 15, 2025
-
2.4
LOWCVE-2019-8548
An issue existed where partially entered passcodes may not clear when the device went to sleep. This issue was addressed by clearing the passcode when a locked device sleeps. This issue is fixed in watchOS 5.2. A partially entered passcode may not clear w... Read more
Affected Products : watchos- EPSS Score: %0.12
- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2021-41181
Nextcloud talk is a self hosting messaging service. In versions prior to 12.3.0 the Nextcloud Android Talk application did not properly detect the lockscreen state when a call was incoming. If an attacker got physical access to the locked phone, and the v... Read more
- EPSS Score: %0.05
- Published: Mar. 08, 2022
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2010-3513
Unspecified vulnerability in Oracle Solaris 9 and 10, and OpenSolaris, allows local users to affect integrity and availability via unknown vectors related to Device Drivers.... Read more
- EPSS Score: %0.10
- Published: Oct. 14, 2010
- Modified: Apr. 11, 2025
-
2.4
LOWCVE-2021-1755
A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A person with physical access to an iOS device may be able to access contacts from the... Read more
Affected Products : macos- EPSS Score: %0.13
- Published: Apr. 02, 2021
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2021-25409
Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device.... Read more
- EPSS Score: %0.02
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2017-18673
An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can disable the Location service on a locked device, making it impossible for the rightful owner to find a stolen device. The Samsung ID is SVE-2017-8524 (May 2017).... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Apr. 07, 2020
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2020-16230
All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that c... Read more
- EPSS Score: %0.04
- Published: Sep. 18, 2020
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2021-40089
An issue was discovered in PrimeKey EJBCA before 7.6.0. The General Purpose Custom Publisher, which is normally run to invoke a local script upon a publishing operation, was still able to run if the System Configuration setting Enable External Script Acce... Read more
Affected Products : ejbca- EPSS Score: %0.05
- Published: Aug. 25, 2021
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2014-2495
Unspecified vulnerability in the PeopleSoft Enterprise SCM Purchasing component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via unknown vectors related to Purchasing.... Read more
Affected Products : peoplesoft_products- EPSS Score: %0.53
- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025
-
2.3
LOWCVE-2019-10165
OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to... Read more
- EPSS Score: %0.06
- Published: Jul. 30, 2019
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2007-3442
Format string vulnerability on the Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 allows remote attackers to cause a denial of service (blocked call reception and calling) via format string specifiers in an SIP INVITE message that lacks a ho... Read more
Affected Products : blackberry_7270- EPSS Score: %0.26
- Published: Jun. 27, 2007
- Modified: Apr. 09, 2025
-
2.3
LOWCVE-2025-8448
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credential data when an attacker is able to capture local SMB traffic between a valid user within the BMS network an... Read more
Affected Products :- Published: Aug. 20, 2025
- Modified: Aug. 20, 2025
- Vuln Type: Information Disclosure
-
2.3
LOWCVE-2025-43733
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7 allows a remote authenticated attacker to inject JavaScript code via the content page's name field. This malicious payload is... Read more
- Published: Aug. 18, 2025
- Modified: Aug. 18, 2025
- Vuln Type: Cross-Site Scripting
-
2.3
LOWCVE-2022-33686
Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.... Read more
- EPSS Score: %0.02
- Published: Jul. 12, 2022
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2020-11932
It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.... Read more
Affected Products : subiquity- EPSS Score: %1.71
- Published: May. 13, 2020
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2025-24806
Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. If users are allowed to sign in via both username and email the regulation system treats the... Read more
Affected Products : authelia- Published: Feb. 19, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Authentication
-
2.3
LOWCVE-2024-6580
The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or certificate. To be exploitable, an application calling the SFTPServer component must grant user... Read more
Affected Products :- Published: Jul. 08, 2024
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2018-12217
Insufficient access control in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373... Read more
Affected Products : graphics_driver- EPSS Score: %0.11
- Published: Mar. 14, 2019
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2024-36469
Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.... Read more
Affected Products : zabbix- Published: Apr. 02, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Authentication