Latest CVE Feed
-
2.7
LOWCVE-2025-1088
In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher.... Read more
Affected Products : grafana- Published: Jun. 18, 2025
- Modified: Jun. 18, 2025
- Vuln Type: Denial of Service
-
2.7
LOWCVE-2024-7296
An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowe... Read more
Affected Products : gitlab- Published: Mar. 13, 2025
- Modified: Aug. 06, 2025
- Vuln Type: Authorization
-
2.7
LOWCVE-2024-28214
nGrinder before 3.5.9 allows to set delay without limitation, which could be the cause of Denial of Service by remote attacker.... Read more
Affected Products : ngrinder- Published: Mar. 07, 2024
- Modified: May. 07, 2025
-
2.7
LOWCVE-2024-47577
Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for customer to manage their accounts, the request url includes customer data and it is recorded in ... Read more
Affected Products : commerce_cloud- Published: Dec. 10, 2024
- Modified: Dec. 10, 2024
-
2.7
LOWCVE-2023-2117
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitize the dir parameter when handling the get_subdirs ajax action, allowing a high privileged users such as admins to inspect names of files and directories outside of the sites root.... Read more
Affected Products : image_optimizer- Published: May. 30, 2023
- Modified: Jan. 10, 2025
-
2.7
LOWCVE-2025-46744
An authenticated administrator could modify the Created By username for a user account... Read more
Affected Products :- Published: May. 12, 2025
- Modified: May. 12, 2025
- Vuln Type: Authorization
-
2.7
LOWCVE-2025-31003
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bogdan Bendziukov Squeeze allows Retrieve Embedded Sensitive Data. This issue affects Squeeze: from n/a through 1.6.... Read more
Affected Products : squeeze- Published: Apr. 09, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Information Disclosure
-
2.7
LOWCVE-2024-42179
HCL MyXalytics is affected by sensitive information disclosure vulnerability. The HTTP response header exposes the Microsoft-HTTP API∕2.0 as the server's name & version.... Read more
Affected Products : dryice_myxalytics- Published: Jan. 12, 2025
- Modified: May. 16, 2025
- Vuln Type: Information Disclosure
-
2.7
LOWCVE-2025-42954
SAP NetWeaver Business Warehouse CCAW application allows a privileged attacker to cause a high CPU load by executing a RFC enabled function modules without any input parameters, which results in reduced performance or interrupted operation of the affected... Read more
Affected Products :- Published: Jul. 08, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Denial of Service
-
2.7
LOWCVE-2025-30681
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Easily exploitable vulnerability allows high privileged attacker with network... Read more
- Published: Apr. 15, 2025
- Modified: Apr. 17, 2025
- Vuln Type: Denial of Service
-
2.7
LOWCVE-2025-49549
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to b... Read more
- Published: Jun. 25, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authorization
-
2.7
LOWCVE-2023-5775
The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due to to the plugin improperly storing backup destination passwords in plaintext. This makes it possi... Read more
Affected Products : backwpup- Published: Feb. 26, 2024
- Modified: Feb. 05, 2025
-
2.7
LOWCVE-2024-20905
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC). Supported versions that are affected are Prior to 9.2.8.0. Easily exploitable vulnerability allows high privileged attacker with ... Read more
Affected Products : jd_edwards_enterpriseone_tools- Published: Feb. 17, 2024
- Modified: Mar. 27, 2025
-
2.7
LOWCVE-2014-4022
The alloc_domain_struct function in arch/arm/domain.c in Xen 4.4.x, when running on an ARM platform, does not properly initialize the structure containing the grant table pages for a domain, which allows local guest administrators to obtain sensitive info... Read more
Affected Products : xen- Published: Jul. 09, 2014
- Modified: Apr. 12, 2025
-
2.7
LOWCVE-2023-27266
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response. ... Read more
- Published: Feb. 27, 2023
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2023-50955
IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the web server installation which could aid in further attacks against the system. IBM X-Force ID: 275777.... Read more
Affected Products : infosphere_information_server- Published: Feb. 21, 2024
- Modified: Dec. 10, 2024
-
2.7
LOWCVE-2022-34452
PowerPath Management Appliance with versions 3.3, 3.2*, 3.1 & 3.0* contains sensitive information disclosure vulnerability. An Authenticated admin user can able to exploit the issue and view sensitive information stored in the logs. ... Read more
Affected Products : powerpath_management_appliance- Published: Feb. 10, 2023
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2024-39353
Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access to the audit logs to read message contents.... Read more
- Published: Jul. 03, 2024
- Modified: Nov. 21, 2024
-
2.7
LOWCVE-2024-55593
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries... Read more
Affected Products : fortiweb- Published: Jan. 14, 2025
- Modified: Feb. 03, 2025
- Vuln Type: Injection
-
2.7
LOWCVE-2023-1084
An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner le... Read more
Affected Products : gitlab- Published: Mar. 09, 2023
- Modified: Nov. 21, 2024