Skip to main content

CWE archive

CWE-313 CVEs

Programmatic archive

30 CVEs tagged with CWE-3131 Critical, 7 High, 16 Medium, 6 Low, 0 Unrated.

CVE-2026-8804

Published Jul 3, 2026

Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-52783

Published Jun 26, 2026

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/SharePoint userless OAuth access_t…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-24349

Published Jun 9, 2026

A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-4397

Published May 7, 2026

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.

CVSS 6.8 · Medium

CVE-2026-6796

Published Apr 21, 2026

A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file core/src/main/java/com/publiccms/controller/admin/LoginAdminCo…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-6598

Published Apr 20, 2026

A security vulnerability has been detected in langflow-ai langflow up to 1.8.3. The affected element is the function create_project/encrypt_auth_settings of the file src/backend/b…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-5531

Published Apr 5, 2026

A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
29.4

CVE-2025-64305

Published Jan 7, 2026

MicroServer copies parts of the system firmware to an unencrypted external SD card on boot, which contains user and vendor secrets. An attacker can utilize these plaintext secrets…

CVSS 7.1 · High

CVE-2025-36154

Published Dec 24, 2025

IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-14836

Published Dec 17, 2025

A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_save.php of the component User Data Storage Module. This mani…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-6748

Published Jun 27, 2025

A vulnerability classified as problematic has been found in Bharti Airtel Thanks App 4.105.4 on Android. Affected is an unknown function of the file /Android/data/com.myairtelapp/…

CVSS 0.9 · Low

CVE-2025-5154

Published May 25, 2025

A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databa…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5098

Published May 23, 2025

PrinterShare Android application allows the capture of Gmail authentication tokens that can be reused to access a user's Gmail account without proper authorization.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-2120

Published Mar 9, 2025

A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226. It has been rated as problematic. This issue affects some unknown processing of the file /tmp/hostapd.c…

CVSS 2.4 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-49762

Published Oct 24, 2024

Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the Panel, a `DELETE` request with their current password in a…

CVSS 4.6 · Medium

CVE-2024-5916

Published Aug 14, 2024

An information exposure vulnerability in Palo Alto Networks PAN-OS software enables a local system administrator to unintentionally disclose secrets, passwords, and tokens of exte…

CVSS 6.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-30406

Published Apr 12, 2024

A Cleartext Storage in a File on Disk vulnerability in Juniper Networks Junos OS Evolved ACX Series devices using the Paragon Active Assurance Test Agent software installed on net…

CVSS 6.7 · Medium
Showing 1-25 of 30 CVEsPage 1 of 2