Latest CVE Feed
-
2.4
LOWCVE-2025-49546
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that could lead to a partial application denial-of-service. A high-privileged attacker could exploit this vulnerability to partially disrupt ... Read more
Affected Products : coldfusion- Published: Jul. 08, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Authorization
-
2.4
LOWCVE-2024-34649
Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.... Read more
- Published: Sep. 04, 2024
- Modified: Sep. 05, 2024
-
2.4
LOWCVE-2022-31224
Dell BIOS versions contain an Improper Protection Against Voltage and Clock Glitches vulnerability. An attacker with physical access to the system could potentially exploit this vulnerability by triggering a fault condition in order to change the behavior... Read more
- Published: Sep. 12, 2022
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2024-46383
Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintext.... Read more
Affected Products :- Published: Nov. 15, 2024
- Modified: Nov. 18, 2024
-
2.4
LOWCVE-2020-1797
HUAWEI Mate 20 smartphones with versions earlier than 10.0.0.185(C00E74R3P8) have an improper authorization vulnerability. The system does not properly restrict certain operation in ADB mode, successful exploit could allow certain user break the limit of ... Read more
- Published: May. 29, 2020
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2019-8742
The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 13. A person with physical access to an iOS device may be able to access contacts from the lock screen.... Read more
Affected Products : iphone_os- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2023-29063
The FACSChorus workstation does not prevent physical access to its PCI express (PCIe) slots, which could allow a threat actor to insert a PCI card designed for memory capture. A threat actor can then isolate sensitive information such as a BitLocker encry... Read more
- Published: Nov. 28, 2023
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2006-6476
FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and when the agent is bound to 0.0.0.0 (all interfaces), opens sockets in non-exclusive mode, which allows local users to hijack the socket, and capture data or cause a den... Read more
Affected Products : first_response- Published: Dec. 20, 2006
- Modified: Apr. 09, 2025
-
2.4
LOWCVE-2024-3430
A vulnerability was found in QKSMS up to 3.9.4 on Android. It has been classified as problematic. This affects an unknown part of the file androidmanifest.xml of the component Backup File Handler. The manipulation leads to exposure of backup file to an un... Read more
Affected Products :- Published: Apr. 07, 2024
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2023-39843
Missing encryption in the RFID tag of Suleve 5-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.... Read more
- Published: Aug. 15, 2023
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2018-4238
An issue was discovered in certain Apple products. iOS before 11.4 is affected. The issue involves the "Siri" component. It allows physically proximate attackers to bypass the lock-screen protection mechanism and enable Siri.... Read more
Affected Products : iphone_os- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2025-24193
This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker with a USB-C connection to an unlocked device may be able to programmatically access photos.... Read more
- Published: Mar. 31, 2025
- Modified: Apr. 07, 2025
- Vuln Type: Authentication
-
2.4
LOWCVE-2022-32872
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 16, iOS 15.7 and iPadOS 15.7. A person with physical access to an iOS device may be able to access photos from the lock screen.... Read more
- Published: Sep. 20, 2022
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2023-32365
The issue was addressed with improved checks. This issue is fixed in iOS 15.7.6 and iPadOS 15.7.6, iOS 16.5 and iPadOS 16.5. Shake-to-undo may allow a deleted photo to be re-surfaced without authentication.... Read more
- Published: Jun. 23, 2023
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2023-32390
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. Photos belonging to the Hidden Photos Album could be viewed without authentication through Visual Lookup.... Read more
- Published: Jun. 23, 2023
- Modified: Dec. 05, 2024
-
2.4
LOWCVE-2023-32394
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information from the lock screen.... Read more
- Published: Jun. 23, 2023
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2019-14355
On ShapeShift KeepKey devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hard... Read more
- Published: Aug. 10, 2019
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2020-4197
IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 174908.... Read more
- Published: Mar. 03, 2020
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2019-14354
On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, ... Read more
- Published: Aug. 10, 2019
- Modified: Nov. 21, 2024
-
2.4
LOWCVE-2017-7407
The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument e... Read more
Affected Products : curl- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025