Latest CVE Feed
-
1.8
LOWCVE-2012-2423
The intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, provide different responses to remote requests depending on whether a ZIP... Read more
- EPSS Score: %0.13
- Published: Apr. 25, 2012
- Modified: Apr. 11, 2025
-
1.8
LOWCVE-2025-47278
Flask is a web server gateway interface (WSGI) web application framework. In Flask 3.1.0, the way fallback key configuration was handled resulted in the last fallback key being used for signing, rather than the current signing key. Signing is provided by ... Read more
Affected Products : flask- Published: May. 13, 2025
- Modified: May. 13, 2025
-
1.8
LOWCVE-2014-4812
The installer in IBM Security AppScan Source 8.x and 9.x through 9.0.1 has an open network port for a debug service, which allows remote attackers to obtain sensitive information by connecting to this port.... Read more
Affected Products : security_appscan_source- EPSS Score: %0.11
- Published: Oct. 26, 2014
- Modified: Apr. 12, 2025
-
1.8
LOWCVE-2021-2147
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Installation). The supported version that is affected is 8.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure w... Read more
- EPSS Score: %0.08
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
1.8
LOWCVE-2024-2567
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, was found in jurecapuder AndroidWeatherApp 1.0.0 on Android. Affected is an unknown function of the file androidmanifest.xml of the component Backup File Handler. The ma... Read more
Affected Products :- Published: Mar. 17, 2024
- Modified: Nov. 21, 2024
-
1.8
LOWCVE-2024-5532
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent. The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal... Read more
Affected Products :- Published: Oct. 28, 2024
- Modified: Oct. 29, 2024
-
1.8
LOWCVE-2024-36119
Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the `user:register_form` tag will have their password confirmation stored in plain text in their user file. This only affects sites matchin... Read more
Affected Products : statamic- Published: May. 30, 2024
- Modified: Nov. 21, 2024
-
1.8
LOWCVE-2024-51746
Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the wrong Rekor entry to use during online verification when multiple entries are returned by the log. gitsign uses Rekor's search API to ... Read more
Affected Products : gitsign- Published: Nov. 05, 2024
- Modified: Nov. 06, 2024
-
1.8
LOWCVE-2019-3008
Vulnerability in the Oracle Solaris product of Oracle Systems (component: LDAP Library). The supported version that is affected is 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris... Read more
- EPSS Score: %0.28
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
1.8
LOWCVE-2012-2421
Absolute path traversal vulnerability in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, might allow remote attackers to ... Read more
- EPSS Score: %0.12
- Published: Apr. 25, 2012
- Modified: Apr. 11, 2025
-
1.8
LOWCVE-2025-30166
Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. An HTML injection issue allows users with access to the email sending functionality to inject arbitrary HTML code into emails sent via the admin interface, potentially leading to session co... Read more
Affected Products : admin_classic_bundle- Published: Apr. 08, 2025
- Modified: Apr. 08, 2025
-
1.8
LOWCVE-2016-0453
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.1.2 allows remote attackers to affect integrity via unknown vectors related to Embedded Server.... Read more
- EPSS Score: %0.52
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.8
LOWCVE-2025-0885
Incorrect Authorization vulnerability in OpenText™ GroupWise allows Exploiting Incorrectly Configured Access Control Security Levels. The vulnerability could allow unauthorized access to calendar items marked private. This issue affects GroupWise versio... Read more
Affected Products :- Published: Jul. 03, 2025
- Modified: Jul. 03, 2025
-
1.8
LOWCVE-2024-12057
User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is not compatible with that of the PcVue Web back end. By exploiting this vulnerability, an attacker could retrieve the ... Read more
Affected Products :- Published: Dec. 09, 2024
- Modified: Dec. 09, 2024
-
1.7
LOWCVE-2011-1820
IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2.0.16 (aka 6.2.0.3-TIV-ITDS-IF0002), and 6.3 before 6.3.0.3 (aka 6.3.... Read more
Affected Products : tivoli_directory_server- EPSS Score: %0.07
- Published: Apr. 21, 2011
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2006-0554
Linux kernel 2.6 before 2.6.15.5 allows local users to obtain sensitive information via a crafted XFS ftruncate call, which may return stale data.... Read more
Affected Products : linux_kernel- EPSS Score: %0.11
- Published: Mar. 07, 2006
- Modified: Apr. 03, 2025
-
1.7
LOWCVE-2013-5865
Unspecified vulnerability in Oracle Solaris 11.1 allows local users to affect availability via unknown vectors related to Utility/User administration.... Read more
- EPSS Score: %0.13
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2006-6107
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).... Read more
Affected Products : d-bus- EPSS Score: %0.10
- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025
-
1.7
LOWCVE-2011-0790
Unspecified vulnerability in Oracle Solaris 9 and 10 allows local users to affect confidentiality via unknown vectors related to wbem.... Read more
- EPSS Score: %0.05
- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
1.7
LOWCVE-2006-0391
Directory traversal vulnerability in the BOM framework in Mac OS X 10.x before 10.3.9 and 10.4 before 10.4.5 allows user-assisted attackers to overwrite or create arbitrary files via an archive that is handled by BOMArchiveHelper.... Read more
Affected Products : mac_os_x- EPSS Score: %0.63
- Published: Mar. 03, 2006
- Modified: Apr. 03, 2025