Skip to main content

CWE archive

CWE-203 CVEs

Programmatic archive

748 CVEs tagged with CWE-20316 Critical, 107 High, 538 Medium, 87 Low, 0 Unrated.

CVE-2013-10006

Published Jan 1, 2023

A vulnerability classified as problematic was found in Ziftr primecoin up to 0.8.4rc1. Affected by this vulnerability is the function HTTPAuthorized of the file src/bitcoinrpc.cpp…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-47952

Published Jan 1, 2023

lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protected directory tree, because "Failed to…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-4823

Published Dec 28, 2022

A vulnerability, which was classified as problematic, was found in InSTEDD Nuntium. Affected is an unknown function of the file app/controllers/geopoll_controller.rb. The manipula…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-4286

Published Dec 27, 2022

A vulnerability, which was classified as problematic, has been found in cocagne pysrp up to 1.0.16. This issue affects the function calculate_x of the file srp/_ctsrp.py. The mani…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-41765

Published Dec 26, 2022

An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes the existence of hidden users.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44381

Published Dec 25, 2022

Snipe-IT through 6.0.14 allows attackers to check whether a user account exists because of response variations in a /password/reset request.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34477

Published Dec 22, 2022

The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could ha…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26382

Published Dec 22, 2022

While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially cr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20559

Published Dec 16, 2022

In revokeOwnPermissionsOnKill of PermissionManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel informati…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-20538

Published Dec 16, 2022

In getSmsRoleHolder of RoleService.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. T…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20535

Published Dec 16, 2022

In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel inf…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-3907

Published Dec 5, 2022

The Clerk WordPress plugin before 4.0.0 is affected by time-based attacks in the validation function for all API requests due to the usage of comparison operators to verify API ke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4087

Published Nov 21, 2022

A vulnerability was found in iPXE. It has been declared as problematic. This vulnerability affects the function tls_new_ciphertext of the file src/net/tls.c of the component TLS.…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-41914

Published Nov 16, 2022

Zulip is an open-source team collaboration tool. For organizations with System for Cross-domain Identity Management(SCIM) account management enabled, Zulip Server 5.0 through 5.6…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-20940

Published Nov 15, 2022

A vulnerability in the TLS handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain access to sensitive information. Thi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-40084

Published Oct 20, 2022

OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a password reset which could enable an attack…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43412

Published Oct 19, 2022

Jenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, pot…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 748 CVEsPage 16 of 30