Skip to main content

CWE archive

CWE-16 CVEs

Programmatic archive

318 CVEs tagged with CWE-1647 Critical, 77 High, 163 Medium, 31 Low, 0 Unrated.

CVE-2026-56586

Published Jul 21, 2026

HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-14971

Published Jul 17, 2026

IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations…

CVSS 3.9 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-4433

Published Mar 24, 2026

An SSH misconfigurations exists in Tenable OT that led to the potential exfiltration of socket, port, and service information via the ostunnel user and GatewayPorts. This could be…

CVSS 1.9 · Low
evidence mentions
1
Buzz score
11.9

CVE-2025-20151

Published May 7, 2025

A vulnerability in the implementation of the Simple Network Management Protocol Version 3 (SNMPv3) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authentic…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-46909

Published Dec 2, 2024

In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-47294

Published Sep 27, 2024

Access permission verification vulnerability in the input method framework module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47291

Published Sep 27, 2024

Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availability.

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42031

Published Aug 8, 2024

Access permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32991

Published May 14, 2024

Permission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability will affect availability.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52719

Published May 14, 2024

Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39385

Published Aug 13, 2023

Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnerability may cause unauthorized access.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-39392

Published Aug 13, 2023

Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43516

Published Dec 5, 2022

A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI)

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28762

Published Oct 14, 2022

Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with 5.10.6 and prior to 5.12.0 contains a debugging port misconfiguration. When camera mode rendering cont…

CVSS 7.3 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2022-37397

Published Aug 12, 2022

An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is e…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22183

Published Apr 14, 2022

An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect to a specific open IPv4 port,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22957

Published Nov 24, 2021

A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 318 CVEsPage 1 of 13