Latest CVE Feed
-
2.3
LOWCVE-2024-36469
Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one.... Read more
Affected Products : zabbix- Published: Apr. 02, 2025
- Modified: Apr. 02, 2025
- Vuln Type: Authentication
-
2.3
LOWCVE-2024-36032
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: qca: fix info leak when fetching fw build id Add the missing sanity checks and move the 255-byte build-id buffer off the stack to avoid leaking stack data through debugfs in ... Read more
Affected Products : linux_kernel- Published: May. 30, 2024
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2017-10292
Vulnerability in the RDBMS Security component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create User privilege with logon to ... Read more
Affected Products : database- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
2.3
LOWCVE-2020-29480
An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting a xenstore watch event. A guest administrator can watch the root xenstored node, which will cause notifications for every created, mod... Read more
- Published: Dec. 15, 2020
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2020-2505
If exploited, this vulnerability could allow attackers to gain sensitive information via generation of error messages. QNAP has already fixed these issues in QES 2.1.1 Build 20201006 and later.... Read more
Affected Products : qes- Published: Dec. 24, 2020
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2014-1652
Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec Web Gateway (SWG) before 5.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified report parameters.... Read more
Affected Products : web_gateway- Published: Jun. 18, 2014
- Modified: Apr. 12, 2025
-
2.3
LOWCVE-2020-0029
In the WifiConfigManager, there is a possible storage of location history which can only be deleted by triggering a factory reset. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for ... Read more
Affected Products : android- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2019-9455
In the Android kernel in the video driver there is a kernel pointer leak due to a WARN_ON statement. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.... Read more
- Published: Sep. 06, 2019
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2023-45152
Engelsystem is a shift planning system for chaos events. A Blind SSRF in the "Import schedule" functionality makes it possible to perform a port scan against the local environment. This vulnerability has been fixed in commit ee7d30b33. If a patch cannot b... Read more
Affected Products : engelsystem- Published: Oct. 17, 2023
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2024-54133
Action Pack is a framework for handling and responding to web requests. There is a possible Cross Site Scripting (XSS) vulnerability in the `content_security_policy` helper starting in version 5.2.0 of Action Pack and prior to versions 7.0.8.7, 7.1.5.1, ... Read more
Affected Products : rails- Published: Dec. 10, 2024
- Modified: Mar. 07, 2025
-
2.3
LOWCVE-2023-20507
An integer overflow in the ASP could allow a privileged attacker to perform an out-of-bounds write, potentially resulting in loss of data integrity.... Read more
Affected Products :- Published: Feb. 11, 2025
- Modified: Feb. 11, 2025
- Vuln Type: Memory Corruption
-
2.3
LOWCVE-2023-31304
Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF) to modify the PCIe® lane count and speed, potentially leading to a loss of availability.... Read more
Affected Products :- Published: Aug. 13, 2024
- Modified: Nov. 04, 2024
-
2.3
LOWCVE-2019-12756
Symantec Endpoint Protection (SEP), prior to 14.2 RU2 may be susceptible to a password protection bypass vulnerability whereby the secondary layer of password protection could by bypassed for individuals with local administrator rights.... Read more
Affected Products : endpoint_protection- Published: Nov. 15, 2019
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2019-4394
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 contain APIs that could be used by a local user to send email. IBM X-Force ID: 162232.... Read more
Affected Products : cloud_orchestrator- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
2.3
LOWCVE-2024-49709
Internet Starter, one of SoftCOM iKSORIS system modules, allows for setting an arbitrary session cookie value. An attacker with an access to user's browser might set such a cookie, wait until the user logs in and then use the same cookie to take over the ... Read more
Affected Products :- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Authentication
-
2.3
LOWCVE-2025-48068
Next.js is a React framework for building full-stack web applications. In versions starting from 13.0 to before 14.2.30 and 15.0.0 to before 15.2.2, Next.js may have allowed limited source code exposure when the dev server was running with the App Router ... Read more
Affected Products : next.js- Published: May. 30, 2025
- Modified: Jun. 13, 2025
- Vuln Type: Information Disclosure
-
2.3
LOWCVE-2025-58160
tracing is a framework for instrumenting Rust programs to collect structured, event-based diagnostic information. Prior to version 0.3.20, tracing-subscriber was vulnerable to ANSI escape sequence injection attacks. Untrusted user input containing ANSI es... Read more
Affected Products :- Published: Aug. 29, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Misconfiguration
-
2.3
LOWCVE-2025-5992
When passing values outside of the expected range to QColorTransferGenericFunction it can cause a denial of service, for example, this can happen when passing a specifically crafted ICC profile to QColorSpace::fromICCProfile.This issue affects Qt from 6.6... Read more
Affected Products :- Published: Jul. 11, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Denial of Service
-
2.3
LOWCVE-2025-54799
Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli as well) don't enforce HTTPS when talking to CAs as an ACME client. Unlike th... Read more
Affected Products :- Published: Aug. 07, 2025
- Modified: Aug. 07, 2025
- Vuln Type: Misconfiguration
-
2.3
LOWCVE-2025-58064
CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions 46.0.0 through 46.0.2 and 44.2.0 through 45.2.1 contain a Cross-Site Scripting (XSS) vulnerability. Ability to exploit could be trigger... Read more
Affected Products : ckeditor5- Published: Sep. 04, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Cross-Site Scripting