Skip to main content

CWE archive

CWE-156 CVEs

Programmatic archive

5 CVEs tagged with CWE-1560 Critical, 0 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2025-55127

Published Nov 20, 2025

HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the username when adding new users. A username with leading or traili…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55001

Published Aug 9, 2025

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, OpenBao allow…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55000

Published Aug 9, 2025

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 0.1.0 through 2.3.1, OpenBao's…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6013

Published Aug 6, 2025

Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set to true and a user had multiple CNs that are equal but wit…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6014

Published Aug 1, 2025

Vault and Vault Enterprise’s (“Vault”) TOTP Secrets Engine code validation endpoint is susceptible to code reuse within its validity period. Fixed in Vault Community Edition 1.20.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1