Skip to main content

CWE archive

CWE-312 CVEs

Programmatic archive

813 CVEs tagged with CWE-31248 Critical, 274 High, 445 Medium, 46 Low, 0 Unrated.

CVE-2021-27205

Published Feb 12, 2021

Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-27204

Published Feb 12, 2021

Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-0337

Published Feb 10, 2021

In moveInMediaStore of FileSystemProvider.java, there is a possible file exposure due to stale metadata. This could lead to local escalation of privilege with User execution privi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23878

Published Feb 10, 2021

Clear text storage of sensitive Information in memory vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local user to view…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20358

Published Feb 8, 2021

IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 stores potentially sensitive information in clear text in API connection log files. This information could be obtained by a user…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29001

Published Jan 26, 2021

An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerabilit…

CVSS 7.2 · High

CVE-2021-1265

Published Jan 20, 2021

A vulnerability in the configuration archive functionality of Cisco DNA Center could allow any privilege-level authenticated, remote attacker to obtain the full unmasked running c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4687

Published Jan 13, 2021

IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5805

Published Jan 8, 2021

In Marvell QConvergeConsole GUI <= 5.5.0.74, credentials are stored in cleartext in tomcat-users.xml. OS-level users on the QCC host who are not authorized to use QCC may use the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24577

Published Jan 8, 2021

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch application discloses sensitive information, such as the hashed admin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 601-625 of 813 CVEsPage 25 of 33