Latest CVE Feed
-
2.1
LOWCVE-2010-0124
Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.... Read more
Affected Products : employee_timeclock_software- EPSS Score: %0.06
- Published: Mar. 15, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2014-8519
Unspecified vulnerability in McAfee Network Data Loss Prevention (NDLP) before 9.2.2 allows local users to read arbitrary files via unknown vectors.... Read more
Affected Products : network_data_loss_prevention- EPSS Score: %0.06
- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2025-53535
Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the originCheck middleware function, which affects the following routes: /verify-email, /reset-password/:token, /delete-user/callback, /magic-lin... Read more
Affected Products : better_auth- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
2.1
LOWCVE-2006-1588
The bridge ioctl (if_bridge code) in NetBSD 1.6 through 3.0 does not clear sensitive memory before copying ioctl results to the requesting process, which allows local users to obtain portions of kernel memory.... Read more
Affected Products : netbsd- EPSS Score: %0.08
- Published: Apr. 03, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-8528
McAfee Network Data Loss Prevention (NDLP) before 9.3 logs session IDs, which allows local users to obtain sensitive information by reading the audit log.... Read more
Affected Products : network_data_loss_prevention- EPSS Score: %0.13
- Published: Oct. 29, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2006-5956
XLineSoft PHPRunner 3.1 stores the (1) database server name, (2) database names, (3) usernames, and (4) passwords in plaintext in %WINDIR%\PHPRunner.ini, which allows local users to obtain sensitive information by reading the file.... Read more
Affected Products : phprunner- EPSS Score: %0.08
- Published: Nov. 17, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2013-0227
Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.... Read more
- EPSS Score: %0.20
- Published: Mar. 19, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-1599
The Siemens SPCanywhere application for iOS allows physically proximate attackers to bypass intended access restrictions by leveraging a filesystem architectural error.... Read more
Affected Products : spcanywhere- EPSS Score: %0.06
- Published: Mar. 07, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2000-0275
CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.... Read more
Affected Products : cryptoadmin- EPSS Score: %0.32
- Published: Apr. 10, 2000
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2000-0019
IMail POP3 daemon uses weak encryption, which allows local users to read files.... Read more
Affected Products : imail- EPSS Score: %0.02
- Published: Mar. 04, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2014-2040
Multiple cross-site scripting (XSS) vulnerabilities in the (1) callback_multicheck, (2) callback_radio, and (3) callback_wysiwygin functions in mfrh_class.settings-api.php in the Media File Renamer plugin 1.7.0 for WordPress allow remote authenticated use... Read more
Affected Products : media_file_renamer- EPSS Score: %0.15
- Published: Mar. 03, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2010-1958
Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitra... Read more
- EPSS Score: %0.25
- Published: Jun. 21, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2013-7128
Valve Bug Reporter in the valve-bugreporter package 2.10+bsos1 in Valve SteamOS Beta stores cleartext credentials in a .valve-bugreporter.cfg file upon a Remember Credentials action, which allows local users to obtain sensitive information by reading this... Read more
Affected Products : steamos- EPSS Score: %0.06
- Published: Dec. 17, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2003-1077
Unknown vulnerability in UFS for Solaris 9 for SPARC, with logging enabled, allows local users to cause a denial of service (UFS file system hang).... Read more
Affected Products : solaris- EPSS Score: %0.07
- Published: Mar. 05, 2003
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2007-0296
Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13, 8.47.11, and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE02.... Read more
- EPSS Score: %0.36
- Published: Jan. 17, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2015-3978
SAP Sybase Unwired Platform Online Data Proxy allows local users to obtain usernames and passwords via the DataVault, aka SAP Security Note 2094830.... Read more
Affected Products : sybase_unwired_platform_online_data_proxy- EPSS Score: %0.06
- Published: May. 12, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-6986
The ZippyYum Subway CA Kiosk app 3.4 for iOS uses cleartext storage in SQLite cache databases, which allows attackers to obtain sensitive information by reading data elements, as demonstrated by password elements.... Read more
Affected Products : subway_ordering_for_california- EPSS Score: %0.07
- Published: Dec. 12, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-1999-1010
An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.... Read more
Affected Products : openssh- EPSS Score: %0.24
- Published: Dec. 14, 1999
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-4238
Cross-site scripting (XSS) vulnerability in admin/code/tce_edit_answer.php in TCExam before 11.3.008 allows remote authenticated users with level 5 or greater permissions to inject arbitrary web script or HTML via the question_subject_id parameter.... Read more
Affected Products : tcexam- EPSS Score: %0.18
- Published: Aug. 20, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-2297
Multiple cross-site scripting (XSS) vulnerabilities in the Creative Commons module 6.x-1.x before 6.x-1.1 for Drupal allow remote authenticated users with the administer creative commons permission to inject arbitrary web script or HTML via the (1) creati... Read more
- EPSS Score: %0.35
- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025