Skip to main content

CWE archive

CWE-1270 CVEs

Programmatic archive

8 CVEs tagged with CWE-12704 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-54593

Published Jul 28, 2026

Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpoint accepted any valid panel-s…

CVSS 8.1 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-49499

Published Jul 22, 2026

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote ac…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-59698

Published Dec 2, 2025

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, might allow a physically proximate attacker to gain access to the EOL legacy bootloader.

CVSS 6.8 · Medium

CVE-2023-32188

Published Oct 16, 2024

A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuV…

CVSS 9.4 · Critical

CVE-2023-22644

Published Sep 20, 2023

A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuV…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-2882

Published May 25, 2023

Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse. This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-30524

Published Apr 12, 2023

Jenkins Report Portal Plugin 0.5 and earlier does not mask ReportPortal access tokens displayed on the configuration form, increasing the potential for attackers to observe and ca…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31122

Published Oct 18, 2022

Wire is an encrypted communication and collaboration platform. Versions prior to 2022-07-12/Chart 4.19.0 are subject to Token Recipient Confusion. If an attacker has certain detai…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1