Latest CVE Feed
-
2.0
LOWCVE-2025-22274
It is possible to inject HTML code into the page content using the "content" field in the "Application definition" page. This issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multip... Read more
Affected Products :- Published: Feb. 28, 2025
- Modified: Mar. 05, 2025
-
2.0
LOWCVE-2024-2502
An application can be configured to block boot attempts after consecutive tamper resets are detected, which may not occur as expected. This is possible because the TAMPERRSTCAUSE register may not be properly updated when a level 4 tamper event (a tamper ... Read more
Affected Products :- Published: Aug. 29, 2024
- Modified: Aug. 30, 2024
-
2.0
LOWCVE-2025-1243
The Temporal api-go library prior to version 1.44.1 did not send `update response` information to Data Converter when the proxy package within the api-go module was used in a gRPC proxy prior to transmission. This resulted in information contained within ... Read more
Affected Products :- Published: Feb. 12, 2025
- Modified: Feb. 12, 2025
-
2.0
LOWCVE-2025-21096
Improper buffer restrictions in the firmware for some Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
-
2.0
LOWCVE-2025-47820
Flock Safety Gunshot Detection devices before 1.3 have cleartext storage of code.... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
-
2.0
LOWCVE-2022-27049
Raidrive before v2021.12.35 allows attackers to arbitrarily move log files by pre-creating a mountpoint and log files before Raidrive is installed.... Read more
Affected Products : raidrive- EPSS Score: %0.14
- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024
-
2.0
LOWCVE-2025-40632
Cross-site scripting (XSS) in Icewarp Mail Server affecting version 11.4.0. This vulnerability allows an attacker to modify the “lastLogin” cookie with malicious JavaScript code that will be executed when the page is rendered.... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 16, 2025
-
2.0
LOWCVE-2024-53274
Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `home.vue` containsa reflected XSS vulnerability due to an incorrect sanitization function. An attacke... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
2.0
LOWCVE-2025-47824
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
-
2.0
LOWCVE-2025-24335
Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, which in theory could potentially be used for causing resource exhaustion in the Single RAN baseband OAM service. No practical exploit h... Read more
Affected Products :- Published: Jul. 02, 2025
- Modified: Jul. 03, 2025
-
2.0
LOWCVE-2024-50406
A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data. We have already fixed ... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
-
2.0
LOWCVE-2022-26328
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText Performance Center on Windows allows Cross-Site Scripting (XSS).This issue affects Performance Center: 12.63.... Read more
Affected Products :- Published: Aug. 21, 2024
- Modified: Aug. 21, 2024
-
2.0
LOWCVE-2025-43489
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could deserialize untrusted data without validation. HP has addressed the issue in the latest software update.... Read more
Affected Products : poly_clariti_manager_firmware- Published: Jul. 23, 2025
- Modified: Jul. 25, 2025
-
2.0
LOWCVE-2024-3995
In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.... Read more
Affected Products : helix_alm- Published: Jun. 28, 2024
- Modified: Nov. 21, 2024
-
2.0
LOWCVE-2025-40631
HTTP host header injection vulnerability in Icewarp Mail Server affecting version 11.4.0. By modifying the Host header and adding a payload, arbitrary JavaScript code can be executed on page load. The user must interact with a malicious link to be redirec... Read more
Affected Products :- Published: May. 16, 2025
- Modified: May. 16, 2025
-
2.0
LOWCVE-2025-2920
A vulnerability was found in Netis WF-2404 1.1.124EN. It has been rated as problematic. This issue affects some unknown processing of the file /еtc/passwd. The manipulation leads to use of weak hash. It is possible to launch the attack on the physical dev... Read more
Affected Products :- Published: Mar. 28, 2025
- Modified: Apr. 01, 2025
-
2.0
LOWCVE-2025-46812
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.15 are vulnerable to XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary ... Read more
Affected Products :- Published: May. 08, 2025
- Modified: May. 12, 2025
-
2.0
LOWCVE-2015-7511
Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.... Read more
- EPSS Score: %0.06
- Published: Apr. 19, 2016
- Modified: Apr. 12, 2025
-
2.0
LOWCVE-2024-57257
A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting.... Read more
Affected Products : u-boot- Published: Feb. 18, 2025
- Modified: Feb. 19, 2025
-
1.9
LOWCVE-2011-1155
The writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a denial of service (rotation outage) via a (1) \n (newline) or (2) \ (backslash) character in a log filename, as demonstrated by a file... Read more
Affected Products : logrotate- EPSS Score: %0.09
- Published: Mar. 30, 2011
- Modified: Apr. 11, 2025