Latest CVE Feed
-
2.2
LOWCVE-2025-47818
Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Misconfiguration
-
2.2
LOWCVE-2024-53564
A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted files. NOTE: the Supplier's position is that there is no risk beyond what... Read more
Affected Products : freepbx- Published: Dec. 02, 2024
- Modified: Jan. 09, 2025
-
2.2
LOWCVE-2024-29208
An Unverified Password Change could allow a malicious actor with API access to the device to change the system password without knowing the previous password. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connect EV... Read more
Affected Products :- Published: May. 07, 2024
- Modified: Nov. 21, 2024
-
2.1
LOWCVE-2015-1355
Siemens SIMATIC STEP 7 (TIA Portal) before 13 SP1 uses a weak password-hash algorithm, which makes it easier for local users to determine cleartext passwords by reading a project file and conducting a brute-force attack.... Read more
Affected Products : simatic_step_7- EPSS Score: %0.06
- Published: Feb. 18, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-0976
Cross-site scripting (XSS) vulnerability in admin/EditForm in SilverStripe 2.4.6 allows remote authenticated users with Content Authors privileges to inject arbitrary web script or HTML via the Title parameter. NOTE: some of these details are obtained fr... Read more
Affected Products : silverstripe- EPSS Score: %0.38
- Published: Feb. 02, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-5056
Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrictions and read a ticket by watching this ticket, and then... Read more
Affected Products : otrs- EPSS Score: %0.16
- Published: Mar. 18, 2011
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-0800
The form-autocompletion functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 makes it easier for physically proximate attackers to discover passwords by reading the contents of a non-password field, as demonstrated by acc... Read more
Affected Products : moodle- EPSS Score: %0.07
- Published: Jul. 17, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2000-0274
The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a long name.... Read more
Affected Products : linux_trustees- EPSS Score: %0.78
- Published: Apr. 10, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-1902
fold_binary in fold-const.c in GNU Compiler Collection (gcc) 4.1 improperly handles pointer overflow when folding a certain expr comparison to a corresponding offset comparison in cases other than EQ_EXPR and NE_EXPR, which might introduce buffer overflow... Read more
Affected Products : gcc- EPSS Score: %0.09
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-8534
Unspecified vulnerability in the login form in McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to cause a denial of service via a crafted value in the domain field.... Read more
Affected Products : network_data_loss_prevention- EPSS Score: %0.05
- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-2125
Multiple cross-site scripting (XSS) vulnerabilities in the Rotor Banner module 5.x before 5.x-1.8 and 6.x before 6.x-2.5 for Drupal allow remote authenticated users, with "create rotor item" or "edit any rotor item" privileges, to inject arbitrary web scr... Read more
- EPSS Score: %0.25
- Published: Jun. 01, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-1999-1449
SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.... Read more
Affected Products : sunos- EPSS Score: %0.05
- Published: May. 19, 1997
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2015-1996
IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not prevent caching of HTTPS responses, which allows physically proximate attackers to obtain sensitive local-cache information by leveraging an unattended workstation.... Read more
- EPSS Score: %0.06
- Published: Nov. 08, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-0095
Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Web, a different vulnerability than CVE-2012... Read more
Affected Products : fusion_middleware- EPSS Score: %0.14
- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-4493
Cross-site scripting (XSS) vulnerability in the administrative interface in the Better Revisions module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer better revisions" permission to inject arbitrary web script or... Read more
- EPSS Score: %0.20
- Published: Nov. 02, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-8537
McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to obtain sensitive information by reading the logs.... Read more
Affected Products : network_data_loss_prevention- EPSS Score: %0.06
- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2001-1551
Linux kernel 2.2.19 enables CAP_SYS_RESOURCE for setuid processes, which allows local users to exceed disk quota restrictions during execution of setuid programs.... Read more
Affected Products : linux_kernel- EPSS Score: %0.08
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-1999-0132
Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.... Read more
- EPSS Score: %0.59
- Published: Aug. 15, 1996
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-1786
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Company theme before 7.x-1.4 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.23
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2005-1914
CenterICQ 4.20.0 and earlier creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack on the gg.token.PID temporary file.... Read more
Affected Products : centericq- EPSS Score: %0.18
- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025