Latest CVE Feed
-
2.2
LOWCVE-2025-47818
Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Misconfiguration
-
2.2
LOWCVE-2025-47821
Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system.... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Authentication
-
2.2
LOWCVE-2024-4811
In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.... Read more
- Published: Jul. 25, 2024
- Modified: Jul. 02, 2025
-
2.2
LOWCVE-2024-29206
An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) and make unsupported changes to the system. Affected Products: UniFi Connect EV Station (Version 1.1.18 and earlier) UniFi Connec... Read more
Affected Products :- Published: May. 07, 2024
- Modified: Nov. 21, 2024
-
2.2
LOWCVE-2024-53861
pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`. This is a bug introduced in version 2.10.0: checking the "iss" claim changed from `isinstance(... Read more
Affected Products : pyjwt- Published: Nov. 29, 2024
- Modified: Dec. 02, 2024
-
2.2
LOWCVE-2024-51754
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list (arguments to a function or... Read more
Affected Products : twig- Published: Nov. 06, 2024
- Modified: May. 29, 2025
-
2.2
LOWCVE-2024-51755
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the `__isset()` method is now called after the sec... Read more
Affected Products : twig- Published: Nov. 06, 2024
- Modified: Nov. 08, 2024
-
2.2
LOWCVE-2024-23843
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Genians Genian NAC V5.0, Genians Genian NAC LTS V5.0.This issue affects Genian NAC V5.0: from V5.0.0 through V5.0.60; Genian NAC LTS V5.0: from 5.0.0 LTS... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 28, 2024
-
2.2
LOWCVE-2023-23349
Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed a local user to recover the auto-filled credentials from a memory dump when the KPM extension for Google Chrome is used. To exploit the issue, an attacker mu... Read more
Affected Products :- Published: Mar. 22, 2024
- Modified: Nov. 21, 2024
-
2.2
LOWCVE-2023-22010
Vulnerability in Oracle Essbase (component: Security and Provisioning). The supported version that is affected is 21.4.3.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Essbase. ... Read more
Affected Products : essbase- Published: Jul. 18, 2023
- Modified: Nov. 21, 2024
-
2.2
LOWCVE-2024-21101
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.33 and prior, 7.6.29 and prior, 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows high p... Read more
- Published: Apr. 16, 2024
- Modified: Feb. 10, 2025
-
2.2
LOWCVE-2024-21243
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network acces... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
2.2
LOWCVE-2024-21244
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network acces... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 16, 2024
-
2.2
LOWCVE-2017-1000401
The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, <f:password/>, supports form validation (e.g. for API keys). The form validation AJAX requests were sent via GET, which could result in secrets being lo... Read more
Affected Products : jenkins- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
2.2
LOWCVE-2025-6227
Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite ... Read more
Affected Products : mattermost_server- Published: Jul. 18, 2025
- Modified: Jul. 22, 2025
- Vuln Type: Authentication
-
2.1
LOWCVE-2007-2448
Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn ... Read more
- Published: Jun. 14, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-1999-1572
cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files.... Read more
Affected Products : enterprise_linux debian_linux enterprise_linux_desktop freebsd ubuntu_linux mandrake_linux- Published: Jul. 16, 1996
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-2110
Virtual Private Server (Vserver) 2.0.x before 2.0.2-rc18 and 2.1.x before 2.1.1-rc18 provides certain context capabilities (ccaps) that allow local guest users to perform operations that were only intended to be allowed by the guest-root.... Read more
Affected Products : vserver- Published: May. 01, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-2071
Linux kernel 2.4.x and 2.6.x up to 2.6.16 allows local users to bypass IPC permissions and modify a readonly attachment of shared memory by using mprotect to give write permission to the attachment. NOTE: some original raw sources combined this issue wit... Read more
- Published: Apr. 27, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2006-0512
PADL MigrationTools 46 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the temporary files, which are not properly created by (1) migrate_all_online.sh, (2) migrate_all_offline.sh, (3) migr... Read more
Affected Products : migrationtools- Published: Feb. 02, 2006
- Modified: Apr. 03, 2025