Skip to main content

CWE archive

CWE-203 CVEs

Programmatic archive

748 CVEs tagged with CWE-20316 Critical, 107 High, 538 Medium, 87 Low, 0 Unrated.

CVE-2022-34125

Published Apr 16, 2023

front/icon.send.php in the CMDB plugin before 3.0.3 for GLPI allows attackers to gain read access to sensitive information via a _log/ pathname in the file parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29850

Published Apr 14, 2023

SENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain information such as the user's geolocation a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27464

Published Apr 11, 2023

A vulnerability has been identified in Mendix Forgot Password (Mendix 7 compatible) (All versions < V3.7.1), Mendix Forgot Password (Mendix 8 compatible) (All versions < V4.1.1),…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28840

Published Apr 4, 2023

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-25000

Published Mar 30, 2023

HashiCorp Vault's implementation of Shamir's secret sharing used precomputed table lookups, and was vulnerable to cache-timing attacks. An attacker with access to, and the ability…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26071

Published Mar 28, 2023

An issue was discovered in MCUBO ICT through 10.12.4 (aka 6.0.2). An Observable Response Discrepancy can occur under the login web page. In particular, the web application provide…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41354

Published Mar 27, 2023

An access control issue in Argo CD v2.4.12 and below allows unauthenticated attackers to enumerate existing applications.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-46876

Published Mar 12, 2023

An issue was discovered in eZ Publish Ibexa Kernel before 7.5.15.1. The /user/sessions endpoint can be abused to determine account existence.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39228

Published Mar 1, 2023

vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. vantage6 does not inform the user of wrong username/password combination if the use…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12413

Published Feb 16, 2023

The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2010-10006

Published Jan 18, 2023

A vulnerability, which was classified as problematic, was found in michaelliao jopenid. Affected is the function getAuthentication of the file JOpenId/src/org/expressme/openid/Ope…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-4543

Published Jan 11, 2023

A flaw named "EntryBleed" was found in the Linux Kernel Page Table Isolation (KPTI). This issue could allow a local attacker to leak KASLR base via prefetch side-channels based on…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-30332

Published Jan 10, 2023

In Talend Administration Center 7.3.1.20200219 before TAC-15950, the Forgot Password feature provides different error messages for invalid reset attempts depending on whether the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4025

Published Jan 2, 2023

Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to leak cross-origin data outside an iframe via a crafted HTML page. (Chrome…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 351-375 of 748 CVEsPage 15 of 30