Skip to main content

CWE archive

CWE-203 CVEs

Programmatic archive

748 CVEs tagged with CWE-20316 Critical, 107 High, 538 Medium, 87 Low, 0 Unrated.

CVE-2023-33518

Published Jun 5, 2023

emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain the web directory path and other information leaked by the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25741

Published Jun 2, 2023

When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24695

Published Jun 2, 2023

Bluetooth Classic in Bluetooth Core Specification through 5.3 does not properly conceal device information for Bluetooth transceivers in Non-Discoverable mode. By conducting an ef…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32342

Published May 30, 2023

IBM GSKit could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large num…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32691

Published May 30, 2023

gost (GO Simple Tunnel) is a simple tunnel written in golang. Sensitive secrets such as passwords, token and API keys should be compared only using a constant-time comparison func…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24598

Published May 29, 2023

OX App Suite before backend 7.10.6-rev37 has an information leak in the handling of distribution lists, e.g., partial disclosure of the private contacts of another user.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26215

Published May 25, 2023

The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that allows an attacker with low-privileged application access to read system files that…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32694

Published May 25, 2023

Saleor Core is a composable, headless commerce API. Saleor's `validate_hmac_signature` function is vulnerable to timing attacks. Malicious users could abuse this vulnerability on…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28015

Published May 23, 2023

The HCL Domino AppDev Pack IAM service is susceptible to a User Account Enumeration vulnerability.   During a failed login attempt a difference in messages could allow an attacker…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28412

Published May 22, 2023

When supplied with a random MAC address, Snap One OvrC cloud servers will return information about the device. The MAC address of devices can be enumerated in an attack and the Ov…

CVSS 5.3 · Medium

CVE-2023-1696

Published May 20, 2023

The multimedia video module has a vulnerability in data processing.Successful exploitation of this vulnerability may affect availability.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23449

Published May 15, 2023

Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain inform…

CVSS 5.3 · Medium

CVE-2023-27870

Published May 11, 2023

IBM Spectrum Virtualize 8.5, under certain circumstances, could disclose sensitive credential information while a download from Fix Central is in progress. IBM X-Force ID: 249518.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26560

Published Apr 26, 2023

Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-40482

Published Apr 25, 2023

The authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks with HTTP/2 multiplexing. This i…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26557

Published Apr 21, 2023

io.finnet tss-lib before 2.0.0 can leak the lambda value of a private key via a timing side-channel attack because it relies on Go big.Int, which is not constant time for Cmp, mod…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26556

Published Apr 21, 2023

io.finnet tss-lib before 2.0.0 can leak a secret key via a timing side-channel attack because it relies on the scalar-multiplication implementation in Go crypto/elliptic, which is…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort
Showing 326-350 of 748 CVEsPage 14 of 30