CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| 1mo ago | 2.4 | On Ledger Nano S and Nano X devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this behavior to recover confidential secrets such as the PIN and BIP39 mnemonic. In other words, the side channel is relevant only if the attacker has enough control over the device's USB connection to make power-consumption measurements at a time when secret data is displayed. The side channel is not relevant in other circumstances, such as a stolen device that is not currently displaying secret data. |
| Exploit 1mo ago | 3.3 | Huawei smart phones Honor V20 with the versions before 9.0.1.161(C00E161R2P2) have an information leak vulnerability. An attacker may trick a user into installing a malicious application. Due to coding error during layer information processing, attackers can exploit this vulnerability to obtain some layer information. |
| 1mo ago | 3.3 | cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130). |
| Exploit 1mo ago | 3.3 | Firefly III 4.7.17.3 is vulnerable to local file enumeration. An attacker can enumerate local files due to the lack of protocol scheme sanitization, such as for file:/// URLs. This is related to fints_url to import/job/configuration, and import/create/fints. |
| 1mo ago | 3.3 | Processing a specially crafted project file in LAquis SCADA 4.3.1.71 may trigger an out-of-bounds read, which may allow an attacker to obtain sensitive information. The attacker must have local access to the system. A CVSS v3 base score of 2.5 has been calculated; the CVSS vector string is (AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N). |
| 1mo ago | 3.3 | cPanel before 60.0.25 does not enforce feature-list restrictions when calling the multilang adminbin (SEC-168). |
| 1mo ago | 2.7 | cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configuration (SEC-228). |
| 1mo ago | 3.3 | cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219). |
| 1mo ago | 2.7 | In cPanel before 62.0.17, addon domain conversion did not require a package for resellers (SEC-208). |
| 1mo ago | 3.5 | cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239). |
| 1mo ago | 3.3 | In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291). |
| 1mo ago | 2.5 | In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290). |
| 1mo ago | 3.3 | In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289). |
| 1mo ago | 2.7 | cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288). |
| 1mo ago | 2.5 | In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280). |
| 1mo ago | 3.3 | In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274). |
| 1mo ago | 3.3 | In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273). |
| 1mo ago | 3.3 | In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272). |
| 1mo ago | 3.3 | cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271). |
| 1mo ago | 2.5 | cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296). |
| 1mo ago | 3.1 | cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341). |
| 1mo ago | 2.7 | cPanel before 68.0.15 allows user accounts to be partially created with invalid username formats (SEC-334). |
| 1mo ago | 3.7 | cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332). |
| 1mo ago | 3.8 | DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331). |
| 1mo ago | 3.3 | cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330). |
| 1mo ago | 2.7 | cPanel before 68.0.15 does not block a username of ssl (SEC-328). |
| 1mo ago | 2.7 | cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327). |
| 1mo ago | 2.7 | cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326). |
| 1mo ago | 2 | cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325). |
| 1mo ago | 2.5 | cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323). |