Latest CVE Feed
-
2.1
LOWCVE-2006-5659
PAM_extern before 0.2 sends a password as a command line argument, which allows local users to obtain the password by listing the command line arguments, such as ps. NOTE: the provenance of this information is unknown; the details are obtained solely fro... Read more
Affected Products : pam_extern- Published: Nov. 03, 2006
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2012-0095
Unspecified vulnerability in the Oracle Imaging and Process Management component in Oracle Fusion Middleware 10.1.3.6.0 allows remote authenticated users to affect confidentiality via unknown vectors related to Web, a different vulnerability than CVE-2012... Read more
Affected Products : fusion_middleware- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2025-53535
Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the originCheck middleware function, which affects the following routes: /verify-email, /reset-password/:token, /delete-user/callback, /magic-lin... Read more
Affected Products : better_auth- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Authentication
-
2.1
LOWCVE-2014-4835
IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.... Read more
- Published: Jan. 17, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2006-2205
The audio_write function in NetBSD 3.0 allows local users to cause a denial of service (kernel crash) by using the audiosetinfo ioctl to change the sample rate of an audio device.... Read more
Affected Products : netbsd- Published: May. 05, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2012-4615
EMC Smarts Network Configuration Manager (NCM) before 9.1 uses a hardcoded encryption key for the storage of credentials, which allows local users to obtain sensitive information via unspecified vectors.... Read more
- Published: Nov. 27, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2012-4899
WellinTech KingView 6.5.3 and earlier uses a weak password-hashing algorithm, which makes it easier for local users to discover credentials by reading an unspecified file.... Read more
Affected Products : kingview- Published: Oct. 10, 2012
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-1584
Cross-site scripting (XSS) vulnerability in the Context module before 6.x-2.0-rc4 for Drupal allows remote authenticated users, with Administer Blocks privileges, to inject arbitrary web script or HTML via a block description.... Read more
- Published: May. 19, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2010-2158
Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) phone, or (3)... Read more
- Published: Jun. 07, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2011-0993
SUSE Lifecycle Management Server before 1.1 uses world readable postgres credentials, which allows local users to obtain sensitive information via unspecified vectors.... Read more
Affected Products : suse_lifecycle_management_server- Published: Apr. 16, 2014
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2013-4293
The server in Red Hat JBoss Operations Network (JON) 3.1.2 logs passwords in plaintext, which allows local users to obtain sensitive information by reading the log files.... Read more
Affected Products : jboss_operations_network- Published: Oct. 24, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2009-1680
Safari in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly clear the search history when it is cleared from the Settings application, which allows physically proximate attackers to obtain the search histor... Read more
- Published: Jun. 19, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2010-1996
Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS before 2.0.5 allow remote authenticated users, with certain creation privileges, to inject arbitrary web script or HTML via the (1) content parameter in conjunction with a /admi... Read more
Affected Products : tomatocms- Published: May. 20, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-3949
Sinapsi eSolar Light with firmware before 2.0.3970_schsl_2.2.85 allows attackers to discover cleartext passwords by reading the HTML source code of the mail-configuration page.... Read more
- Published: Jun. 13, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2025-47929
DumbDrop, a file upload application that provides an interface for dragging and dropping files, has a DOM cross-site scripting vulnerability in the upload functionality prior to commit db27b25372eb9071e63583d8faed2111a2b79f1b. A user could be tricked into... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Cross-Site Scripting
-
2.1
LOWCVE-2005-2765
The user interface in the Windows Firewall does not properly display certain malformed entries in the Windows Registry, which makes it easier for attackers with administrator privileges to hide activities if the administrator only uses the Windows Firewal... Read more
- Published: Sep. 01, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0119
helvis 1.8h2_1 and earlier allows local users to recover and read the files of other users via the elvrec setuid program.... Read more
Affected Products : helvis- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2013-1784
Cross-site scripting (XSS) vulnerability in the 3 slide gallery in the Clean Theme before 7.x-1.3 for Drupal allows remote authenticated users with the administer themes permission to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Mar. 27, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2007-1353
The setsockopt function in the L2CAP and HCI Bluetooth support in the Linux kernel before 2.4.34.3 allows context-dependent attackers to read kernel memory and obtain sensitive information via unspecified vectors involving the copy_from_user function acce... Read more
Affected Products : linux_kernel- Published: Apr. 24, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2013-1977
OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admin_token secret by reading the file.... Read more
Affected Products : devstack- Published: May. 21, 2013
- Modified: Apr. 11, 2025