Latest CVE Feed
-
2.6
LOWCVE-1999-0790
A remote attacker can read information from a Netscape user's cache via JavaScript.... Read more
Affected Products : communicator- Published: Apr. 01, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-1999-1001
Cisco Cache Engine allows a remote attacker to gain access via a null username and password.... Read more
Affected Products : cache_engine- Published: Dec. 16, 1999
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2025-0251
HCL IEM is affected by a concurrent login vulnerability. The application allows multiple concurrent sessions using the same user credentials, which may introduce security risks.... Read more
Affected Products :- Published: Jul. 25, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Authentication
-
2.6
LOWCVE-2025-20030
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated user to potentially enable information disclosure via adjacent access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Information Disclosure
-
2.6
LOWCVE-2024-37181
Time-of-check time-of-use race condition in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable information disclosure via adjacent access.... Read more
Affected Products :- Published: Jan. 16, 2025
- Modified: Jan. 16, 2025
- Vuln Type: Race Condition
-
2.6
LOWCVE-2016-1185
The Cybozu kintone mobile application 1.x before 1.0.6 for Android allows attackers to discover an authentication token via a crafted application.... Read more
Affected Products : kintone- Published: Apr. 25, 2016
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2024-32771
An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network authenticated administrators to perform an arbitrary n... Read more
- Published: Sep. 06, 2024
- Modified: Sep. 20, 2024
-
2.6
LOWCVE-2017-0096
Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users to obtain sensitive information from host O... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_vista- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
2.6
LOWCVE-2022-21929
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability... Read more
Affected Products : edge_chromium- Published: Jan. 11, 2022
- Modified: Nov. 21, 2024
-
2.6
LOWCVE-2025-47794
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 29.0.13, 30.0.7, and 31.0.1 and Nextcloud Enterprise Server prior to 26.0.13.13, 27.1.11.13, 28.0.14.4, 29.0.13, 30.0.7, and 31.0.1, an attacker on a multi-user system m... Read more
Affected Products : notes- Published: May. 16, 2025
- Modified: May. 19, 2025
- Vuln Type: Information Disclosure
-
2.6
LOWCVE-2009-4172
Cross-site scripting (XSS) vulnerability in index.php in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews 8 and 8b, when magic_quotes_gpc is disabled, allows remote attackers to inject arbitrary web script or HTML via the body of a news article in an addnews act... Read more
- Published: Dec. 02, 2009
- Modified: Apr. 09, 2025
-
2.6
LOWCVE-2001-0068
Mac OS Runtime for Java (MRJ) 2.2.3 allows remote attackers to use malicious applets to read files outside of the CODEBASE context via the ARCHIVE applet parameter.... Read more
Affected Products : mac_os_runtime_for_java- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2014-2226
Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : unifi_controller- Published: Jul. 29, 2014
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2009-4998
The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-019 and 4.0.2.x before 4.0.2.7-P8AE-FP007, in certain FileTracker configurations, does not apply a security policy to the first document added during a session... Read more
Affected Products : filenet_p8_application_engine- Published: Sep. 20, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2024-41985
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >= V13.2 < V2506), SOA Cockpit (All versions >= V13.2 < V2506). The affected application does not expire the session ... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authentication
-
2.6
LOWCVE-2000-0716
WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijack the session ID and read the user's email.... Read more
Affected Products : mdaemon- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0905
Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property.... Read more
Affected Products : maxthon- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2010-1157
Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm f... Read more
Affected Products : tomcat- Published: Apr. 23, 2010
- Modified: Apr. 11, 2025
-
2.6
LOWCVE-2015-2625
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45; JRockit R28.3.6; and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality via vectors related to JSSE.... Read more
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2004-1449
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7 allows remote attackers to determine the location of files on a user's hard drive by obscuring a file upload control and tricking the user into dragging text into that control.... Read more
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025