Skip to main content

CWE archive

CWE-203 CVEs

Programmatic archive

748 CVEs tagged with CWE-20316 Critical, 107 High, 538 Medium, 87 Low, 0 Unrated.

CVE-2022-43411

Published Oct 19, 2022

Jenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2891

Published Oct 10, 2022

The WP 2FA WordPress plugin before 2.3.0 uses comparison operators that don't mitigate time-based attacks, which could be abused to leak information about the authentication codes…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-40895

Published Oct 6, 2022

In certain Nedi products, a vulnerability in the web UI of NeDi login & Community login could allow an unauthenticated, remote attacker to affect the integrity of a device via a U…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-32218

Published Sep 23, 2022

An information disclosure vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 due to the actionLinkHandler method was found to allow Message ID Enumeration with Regex Mon…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36105

Published Sep 13, 2022

TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that observing response time during user authentication (backend…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37146

Published Sep 8, 2022

The PlexTrac platform prior to version 1.28.0 allows for username enumeration via HTTP response times on invalid login attempts for users configured to use the PlexTrac authentica…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1989

Published Aug 23, 2022

All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to information exposure allowing a remote, unauthenticated attacker to enumerate valid users.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2612

Published Aug 12, 2022

Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who had compromised the renderer process to obtain potentially…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-20324

Published Aug 12, 2022

In Framework, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local inf…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20320

Published Aug 12, 2022

In ActivityManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to loc…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-20318

Published Aug 12, 2022

In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to lo…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-20316

Published Aug 12, 2022

In ContentResolver, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to loc…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-20309

Published Aug 12, 2022

In PackageInstaller, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to lo…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-20307

Published Aug 12, 2022

In AlarmManagerService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-20304

Published Aug 12, 2022

In Content, there is a possible way to determinate the user's account due to side channel information disclosure. This could lead to local information disclosure with User executi…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20293

Published Aug 12, 2022

In LauncherApps, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20291

Published Aug 12, 2022

In AppOpsService, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20279

Published Aug 12, 2022

In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20277

Published Aug 12, 2022

In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20276

Published Aug 12, 2022

In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20275

Published Aug 12, 2022

In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-20252

Published Aug 11, 2022

In PackageManager, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to loca…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 401-425 of 748 CVEsPage 17 of 30