Skip to main content

CWE archive

CWE-290 CVEs

Programmatic archive

631 CVEs tagged with CWE-290107 Critical, 200 High, 296 Medium, 25 Low, 3 Unrated.

CVE-2024-30189

Published Apr 9, 2024

A vulnerability has been identified in SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (All versions), SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AB0) (All versions), SCALANCE W722-1 RJ45 (6G…

CVSS 6.1 · Medium

CVE-2024-29006

Published Apr 4, 2024

By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead to authentication bypass and ot…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-31008

Published Apr 3, 2024

An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php file.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22092

Published Apr 2, 2024

in OpenHarmony v3.2.4 and prior versions allow a remote attacker bypass permission verification to install apps, although these require user action.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28228

Published Mar 7, 2024

In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22457

Published Mar 1, 2024

Dell Secure Connect Gateway 5.20 contains an improper authentication vulnerability during the SRS to SCG update path. A remote low privileged attacker could potentially exploit th…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51747

Published Feb 27, 2024

Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of interpretation between…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-42889

Published Feb 21, 2024

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to bypass certain Privacy p…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1555

Published Feb 20, 2024

When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21494

Published Feb 17, 2024

All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitizatio…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23674

Published Feb 15, 2024

The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a…

CVSS 9.6 · Critical

CVE-2023-7169

Published Feb 8, 2024

Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.This issue affects Snow Inventory Agent: through 6.14.5. Cu…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22520

Published Feb 6, 2024

An issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers to impersonate other drones via transmission of crafted data packets.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-22519

Published Feb 6, 2024

An issue discovered in OpenDroneID OSM 3.5.1 allows attackers to impersonate other drones via transmission of crafted data packets.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23832

Published Feb 1, 2024

Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all M…

CVSS 9.4 · Critical
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2023-6044

Published Jan 19, 2024

A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical access to impersonate Lenovo Vantage Service and execute arbitr…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4566

Published Jan 16, 2024

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-44117

Published Jan 16, 2024

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51350

Published Jan 11, 2024

A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-Forwarded-For function in the…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-41069

Published Jan 10, 2024

This issue was addressed by improving Face ID anti-spoofing models. This issue is fixed in iOS 17 and iPadOS 17. A 3D model constructed to look like the enrolled user may authenti…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 631 CVEsPage 16 of 26