Skip to main content

CWE archive

CWE-312 CVEs

Programmatic archive

823 CVEs tagged with CWE-31249 Critical, 277 High, 450 Medium, 47 Low, 0 Unrated.

CVE-2023-6250

Published Dec 26, 2023

The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50294

Published Dec 26, 2023

The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50719

Published Dec 15, 2023

XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50777

Published Dec 13, 2023

Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job configuration form, increasing the potential for attackers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50776

Published Dec 13, 2023

Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier stores PaaSLane authentication tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50773

Published Dec 13, 2023

Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capt…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50772

Published Dec 13, 2023

Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8314

Published Dec 12, 2023

The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-46141

Published Dec 12, 2023

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulnerability could allow a local attacker to gain access to the…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46384

Published Nov 30, 2023

LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-48707

Published Nov 24, 2023

CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. The `secretKey` value is an important key for HMAC SHA256 authentication and in affected vers…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47312

Published Nov 22, 2023

Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to Login Credential Leakage via Audit Entries.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48305

Published Nov 21, 2023

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Serv…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46376

Published Oct 27, 2023

Zentao Biz version 8.7 and before is vulnerable to Information Disclosure.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-41096

Published Oct 26, 2023

Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41095

Published Oct 26, 2023

Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network c…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46653

Published Oct 25, 2023

Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, potentially resulting in its exposure.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46128

Published Oct 25, 2023

Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 2.0.x, certain REST API endp…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45151

Published Oct 16, 2023

Nextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2 tokens in plaintext which allows an attacker who has gained access to the serv…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 823 CVEsPage 13 of 33