Latest CVE Feed
-
2.0
LOWCVE-2023-45706
An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration. ... Read more
Affected Products : bigfix_platform- Published: Mar. 28, 2024
- Modified: Nov. 21, 2024
-
2.0
LOWCVE-2025-52937
Vulnerability in PointCloudLibrary PCL (surface/src/3rdparty/opennurbs modules). This vulnerability is associated with program files crc32.C. This vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to... Read more
Affected Products :- Published: Jun. 23, 2025
- Modified: Jun. 23, 2025
-
2.0
LOWCVE-2024-52286
Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In affected versions the Merge functionality takes untrusted user input (file name) and uses it directly in the creation of HTML pages allowing an... Read more
Affected Products : stirling_pdf- Published: Nov. 11, 2024
- Modified: Jan. 09, 2025
-
2.0
LOWCVE-2015-7511
Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring electromagnetic emanations.... Read more
- EPSS Score: %0.06
- Published: Apr. 19, 2016
- Modified: Apr. 12, 2025
-
2.0
LOWCVE-2024-3995
In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.... Read more
Affected Products : helix_alm- Published: Jun. 28, 2024
- Modified: Nov. 21, 2024
-
2.0
LOWCVE-2024-52008
Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords by bypassing client-side validation. While the UI enforces passwo... Read more
Affected Products : fides- Published: Nov. 26, 2024
- Modified: Nov. 26, 2024
-
2.0
LOWCVE-2025-2864
SaTECH BCU in its firmware version 2.1.3 allows an attacker to inject malicious code into the legitimate website owning the affected device, once the cookie is set. This attack only impacts the victim's browser (reflected XSS).... Read more
Affected Products :- Published: Mar. 28, 2025
- Modified: Mar. 28, 2025
-
2.0
LOWCVE-2024-38372
Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of memory from the Node.js process. This has been patched in v6.19.2.... Read more
Affected Products : undici- Published: Jul. 08, 2024
- Modified: Nov. 21, 2024
-
2.0
LOWCVE-2024-57257
A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with deep symlink nesting.... Read more
Affected Products : u-boot- Published: Feb. 18, 2025
- Modified: Feb. 19, 2025
- Vuln Type: Denial of Service
-
2.0
LOWCVE-2025-22274
It is possible to inject HTML code into the page content using the "content" field in the "Application definition" page. This issue affects CyberArk Endpoint Privilege Manager in SaaS version 24.7.1. The status of other versions is unknown. After multip... Read more
Affected Products :- Published: Feb. 28, 2025
- Modified: Mar. 05, 2025
- Vuln Type: Cross-Site Scripting
-
2.0
LOWCVE-2025-8573
Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page. Version 8 was not affected. A rogue admin could set up a malicious folder containing XSS to which users could be directed upon login. The Concr... Read more
- Published: Aug. 05, 2025
- Modified: Aug. 11, 2025
- Vuln Type: Cross-Site Scripting
-
2.0
LOWCVE-2025-21096
Improper buffer restrictions in the firmware for some Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: Aug. 12, 2025
- Modified: Aug. 13, 2025
- Vuln Type: Authorization
-
2.0
LOWCVE-2025-5941
Netskope is notified about a potential gap in its agent (NS Client) in which a malicious actor could trigger a memory leak by sending a crafted DNS packet to a machine. A successful exploitation may require administrative privileges on the machine, based ... Read more
Affected Products : netskope- Published: Aug. 14, 2025
- Modified: Aug. 14, 2025
- Vuln Type: Memory Corruption
-
2.0
LOWCVE-2024-21105
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris exec... Read more
- Published: Apr. 16, 2024
- Modified: May. 08, 2025
-
2.0
LOWCVE-2024-50406
A cross-site scripting (XSS) vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers who have gained user access to bypass security mechanisms or read application data. We have already fixed ... Read more
Affected Products :- Published: Jun. 06, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
2.0
LOWCVE-2025-30516
Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content via continued mobile notifications... Read more
Affected Products : mattermost_server- Published: Apr. 14, 2025
- Modified: Apr. 15, 2025
- Vuln Type: Authentication
-
2.0
LOWCVE-2025-0138
Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to unauthorized access. Compute in Prisma Cloud Enterprise Edition is not aff... Read more
Affected Products : prisma_cloud_compute_edition- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication
-
2.0
LOWCVE-2022-26328
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText Performance Center on Windows allows Cross-Site Scripting (XSS).This issue affects Performance Center: 12.63.... Read more
Affected Products :- Published: Aug. 21, 2024
- Modified: Aug. 21, 2024
-
2.0
LOWCVE-2024-12014
Path Traversal vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.... Read more
Affected Products :- Published: Dec. 20, 2024
- Modified: May. 20, 2025
-
2.0
LOWCVE-2025-4762
Insecure Direct Object Reference (IDOR) vulnerability in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths an... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization