Latest CVE Feed
-
2.1
LOWCVE-2010-1636
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the btrfs functionality in the Linux kernel 2.6.29 through 2.6.32, and possibly other versions, does not ensure that a cloned file descriptor has been opened for reading, which allows local users to re... Read more
Affected Products : linux_kernel- EPSS Score: %0.24
- Published: Jun. 08, 2010
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2006-4031
MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table, which might violate intended security policy.... Read more
- EPSS Score: %0.26
- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2009-1631
The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to obtain sensitive information by readi... Read more
Affected Products : evolution- EPSS Score: %0.10
- Published: May. 14, 2009
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2007-0010
The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to cause a denial of service (crash) via a malformed image file.... Read more
Affected Products : gtk- EPSS Score: %0.87
- Published: Jan. 24, 2007
- Modified: Apr. 09, 2025
-
2.1
LOWCVE-2013-4064
Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTH... Read more
- EPSS Score: %0.17
- Published: Dec. 21, 2013
- Modified: Apr. 11, 2025
-
2.1
LOWCVE-2015-7872
The key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 4.2.6 allows local users to cause a denial of service (OOPS) via crafted keyctl commands.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Nov. 16, 2015
- Modified: Apr. 12, 2025
-
2.1
LOWCVE-2012-0961
Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local us... Read more
- EPSS Score: %0.05
- Published: Dec. 26, 2012
- Modified: Apr. 11, 2025
-
2.0
LOWCVE-2025-47824
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Cryptography
-
2.0
LOWCVE-2024-49417
Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.... Read more
Affected Products : smart_touch_call- Published: Dec. 03, 2024
- Modified: Dec. 03, 2024
-
2.0
LOWCVE-2025-0138
Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not aff... Read more
Affected Products : prisma_cloud_compute_edition- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
2.0
LOWCVE-2025-2864
SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie is set. This attack only impacts the victim's browser (reflected XSS).... Read more
Affected Products :- Published: Mar. 28, 2025
- Modified: Mar. 28, 2025
-
2.0
LOWCVE-2024-52286
Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In affected versions the Merge functionality takes untrusted user input (file name) and uses it directly in the creation of HTML pages allowing an... Read more
Affected Products : stirling_pdf- Published: Nov. 11, 2024
- Modified: Jan. 09, 2025
-
2.0
LOWCVE-2025-46812
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.15 are vulnerable to XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary ... Read more
Affected Products :- Published: May. 08, 2025
- Modified: May. 12, 2025
- Vuln Type: Cross-Site Scripting
-
2.0
LOWCVE-2024-2502
An application can be configured to block boot attempts after consecutive tamper resets are detected, which may not occur as expected. This is possible because the TAMPERRSTCAUSE register may not be properly updated when a level 4 tamper event (a tamper ... Read more
Affected Products :- Published: Aug. 29, 2024
- Modified: Aug. 30, 2024
-
2.0
LOWCVE-2024-52008
Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords by bypassing client-side validation. While the UI enforces passwo... Read more
Affected Products : fides- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
2.0
LOWCVE-2024-50406
A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data. We have already fixed ... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
2.0
LOWCVE-2025-30516
Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content via continued mobile notifications... Read more
Affected Products : mattermost_server- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Authentication
-
2.0
LOWCVE-2025-5941
Netskope is notified about a potential gap in its agent (NS Client) in which a malicious actor could trigger a memory leak by sending a crafted DNS packet to a machine. A successful exploitation may require administrative privileges on the machine, based ... Read more
Affected Products : netskope- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Memory Corruption
-
2.0
LOWCVE-2025-47820
Flock Safety Gunshot Detection devices before 1.3 have cleartext storage of code.... Read more
Affected Products :- Published: Jun. 27, 2025
- Modified: Jun. 30, 2025
- Vuln Type: Cryptography
-
2.0
LOWCVE-2025-21096
Improper buffer restrictions in the firmware for some Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Authorization