Latest CVE Feed
-
1.5
LOWCVE-2009-2094
Unspecified vulnerability in IBM WebSphere Commerce 6.0 Enterprise before 6.0.0.8, when trace is enabled, allows local users to obtain sensitive information via unknown vectors.... Read more
Affected Products : websphere_commerce- EPSS Score: %0.05
- Published: Aug. 13, 2009
- Modified: Apr. 09, 2025
-
1.4
LOWCVE-2016-0618
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality via unknown vectors related to Zones.... Read more
Affected Products : solaris- EPSS Score: %0.08
- Published: Jan. 21, 2016
- Modified: Apr. 12, 2025
-
1.4
LOWCVE-2014-2485
Unspecified vulnerability in the Siebel Core - EAI component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows local users to affect confidentiality via unknown vectors related to Integration Business Services.... Read more
Affected Products : siebel_crm- EPSS Score: %0.18
- Published: Jul. 17, 2014
- Modified: Apr. 12, 2025
-
1.3
LOWCVE-2025-53903
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/users.js` doesn't properly sanitize text box inputs, leading to a potential vulnerability to cross-site scripting attacks. Commit 90b39eb56b27b2bac2... Read more
Affected Products :- Published: Jul. 15, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Cross-Site Scripting
-
1.3
LOWCVE-2015-5464
The Gemalto SafeNet Luna HSM allows remote authenticated users to bypass intended key-export restrictions by leveraging (1) crypto-user or (2) crypto-officer access to an HSM partition.... Read more
- EPSS Score: %0.06
- Published: Jul. 22, 2015
- Modified: Apr. 12, 2025
-
1.3
LOWCVE-2025-53904
The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make the website vulnerable to cross-site scripting. No known patches exist as of time of publication.... Read more
Affected Products :- Published: Jul. 16, 2025
- Modified: Jul. 17, 2025
- Vuln Type: Cross-Site Scripting
-
1.3
LOWCVE-2025-53374
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications and databases. An authenticated low-privileged account can retrieve detailed profile information about another users in the same organiza... Read more
Affected Products :- Published: Jul. 07, 2025
- Modified: Jul. 08, 2025
- Vuln Type: Information Disclosure
-
1.3
LOWCVE-2011-2242
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.2.0.1 and 11.2.0.2 allows local users to affect confidentiality, related to XML DB FTP.... Read more
Affected Products : database_server- EPSS Score: %0.30
- Published: Jul. 20, 2011
- Modified: Apr. 11, 2025
-
1.3
LOWCVE-2025-46826
insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's secondary authentication bridge, potentially revealing basic student information (name and number). However, the issue posed minimal ri... Read more
Affected Products :- Published: May. 07, 2025
- Modified: May. 08, 2025
- Vuln Type: Information Disclosure
-
1.2
LOWCVE-2002-1508
slapd in OpenLDAP2 (OpenLDAP 2) 2.2.0 and earlier allows local users to overwrite arbitrary files via a race condition during the creation of a log file for rejected replication requests.... Read more
Affected Products : openldap- EPSS Score: %0.03
- Published: Feb. 19, 2003
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2006-1059
The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain.... Read more
Affected Products : samba- EPSS Score: %0.46
- Published: Mar. 30, 2006
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-0937
Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executin... Read more
- EPSS Score: %0.06
- Published: Feb. 22, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2013-6891
lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.... Read more
- EPSS Score: %0.05
- Published: Jan. 26, 2014
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2011-4617
virtualenv.py in virtualenv before 1.5 allows local users to overwrite arbitrary files via a symlink attack on a certain file in /tmp/.... Read more
- EPSS Score: %0.05
- Published: Dec. 31, 2011
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2001-1331
mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.... Read more
- EPSS Score: %0.07
- Published: May. 03, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2001-0138
privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.... Read more
- EPSS Score: %0.08
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2014-5177
libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) v... Read more
- EPSS Score: %0.11
- Published: Aug. 03, 2014
- Modified: Apr. 12, 2025
-
1.2
LOWCVE-2004-1069
Race condition in SELinux 2.6.x through 2.6.9 allows local users to cause a denial of service (kernel crash) via SOCK_SEQPACKET unix domain sockets, which are not properly handled in the sock_dgram_sendmsg function.... Read more
- EPSS Score: %0.06
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2012-2103
The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.... Read more
Affected Products : munin- EPSS Score: %0.04
- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025
-
1.2
LOWCVE-2009-1707
Race condition in the Reset Safari implementation in Apple Safari before 4.0 on Windows might allow local users to read stored web-site passwords via unspecified vectors.... Read more
Affected Products : safari- EPSS Score: %0.07
- Published: Jun. 10, 2009
- Modified: Apr. 09, 2025