Latest CVE Feed
-
1.5
LOWCVE-2006-0678
PostgreSQL 7.3.x before 7.3.14, 7.4.x before 7.4.12, 8.0.x before 8.0.7, and 8.1.x before 8.1.3, when compiled with Asserts enabled, allows local users to cause a denial of service (server crash) via a crafted SET SESSION AUTHORIZATION command, a differen... Read more
Affected Products : postgresql- EPSS Score: %0.07
- Published: Feb. 14, 2006
- Modified: Apr. 03, 2025
-
1.5
LOWCVE-2016-0498
Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows local users to affect confidentiality via unknown vectors related to Install.... Read more
- EPSS Score: %0.07
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.5
LOWCVE-2013-1546
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 2.8.0 through 3.1.0 and 5.0.2 through 12.0.1 allows local users to affect confidentiality via vectors related to BASE.... Read more
Affected Products : financial_services_software- EPSS Score: %0.11
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
1.5
LOWCVE-2013-0525
Multiple cross-site scripting (XSS) vulnerabilities in IBM iNotes 8.5.x allow local users to inject arbitrary web script or HTML via a shared mail file, aka SPR DKEN8PDNTX.... Read more
Affected Products : lotus_inotes- EPSS Score: %0.09
- Published: Mar. 26, 2013
- Modified: Apr. 11, 2025
-
1.5
LOWCVE-2010-3321
RSA Authentication Client 2.0.x, 3.0, and 3.5.x before 3.5.3 does not properly handle a SENSITIVE or NON-EXTRACTABLE tag on a secret key object that is stored on a SecurID 800 authenticator, which allows local users to bypass intended access restrictions ... Read more
Affected Products : authentication_client- EPSS Score: %0.05
- Published: Oct. 07, 2010
- Modified: Apr. 11, 2025
-
1.5
LOWCVE-2013-2393
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4.0 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters.... Read more
Affected Products : fusion_middleware- EPSS Score: %0.47
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
1.5
LOWCVE-2013-5791
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.4.1 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters. NOTE: the previous informatio... Read more
Affected Products : fusion_middleware- EPSS Score: %25.22
- Published: Oct. 16, 2013
- Modified: Apr. 11, 2025
-
1.5
LOWCVE-2013-4829
HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices allow local users to read images of arbitrary scanned documents... Read more
- EPSS Score: %0.06
- Published: Oct. 04, 2013
- Modified: Apr. 11, 2025
-
1.5
LOWCVE-2011-1637
Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 do not properly verify signatures for software images, which allows local users to gain privileges via a crafted image, aka Bug ID CSCtn65962.... Read more
- EPSS Score: %0.10
- Published: Jun. 02, 2011
- Modified: Apr. 11, 2025
-
1.5
LOWCVE-2015-4877
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-201... Read more
Affected Products : fusion_middleware- EPSS Score: %0.27
- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
1.5
LOWCVE-2009-2752
IBM WebSphere Commerce 7.0 does not properly encrypt data in a database, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms.... Read more
Affected Products : websphere_commerce- EPSS Score: %0.06
- Published: Feb. 05, 2010
- Modified: Apr. 11, 2025
-
1.5
LOWCVE-2008-2587
Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and local attack vectors.... Read more
- EPSS Score: %0.16
- Published: Jul. 15, 2008
- Modified: Apr. 09, 2025
-
1.4
LOWCVE-2016-0618
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality via unknown vectors related to Zones.... Read more
Affected Products : solaris- EPSS Score: %0.08
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.4
LOWCVE-2014-2485
Unspecified vulnerability in the Siebel Core - EAI component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows local users to affect confidentiality via unknown vectors related to Integration Business Services.... Read more
Affected Products : siebel_crm- EPSS Score: %0.18
- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025
-
1.3
LOWCVE-2025-53904
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make the website vulnerable to cross-site scripting. No known patches exist as of time of publication.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
1.3
LOWCVE-2015-5464
The Gemalto SafeNet Luna HSM allows remote authenticated users to bypass intended key-export restrictions by leveraging (1) crypto-user or (2) crypto-officer access to an HSM partition.... Read more
- EPSS Score: %0.06
- Published: Jul. 22, 2015
- Modified: Apr. 12, 2025
-
1.3
LOWCVE-2025-53374
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profile information about another users in the same organiza... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
1.3
LOWCVE-2025-53903
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/users.js` doesn't properly sanitize text box inputs, leading to a potential vulnerability to cross-site scripting attacks. Commit 90b39eb56b27b2bac2... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Cross-Site Scripting
-
1.3
LOWCVE-2025-46826
insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's secondary authentication bridge, potentially revealing basic student information (name and number). However, the issue posed minimal ri... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Information Disclosure
-
1.3
LOWCVE-2011-2242
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.2.0.1 and 11.2.0.2 allows local users to affect confidentiality, related to XML DB FTP.... Read more
Affected Products : database_server- EPSS Score: %0.30
- Published: Jul. 20, 2011
- Modified: Apr. 11, 2025