Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

897 CVEs tagged with CWE-31982 Critical, 359 High, 402 Medium, 54 Low, 0 Unrated.

CVE-2023-46447

Published Jan 20, 2024

The POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted glucose measurements over BLE.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31300

Published Dec 29, 2023

An issue was discovered in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows remote attackers to obtain sensitive information via transmission of unenc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34829

Published Dec 28, 2023

Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28616

Published Dec 26, 2023

An issue was discovered in Stormshield Network Security (SNS) before 4.3.17, 4.4.x through 4.6.x before 4.6.4, and 4.7.x before 4.7.1. It affects user accounts for which the passw…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51390

Published Dec 21, 2023

journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration o…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42579

Published Dec 5, 2023

Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46385

Published Nov 30, 2023

LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so i…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-46383

Published Nov 30, 2023

LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote atta…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-43503

Published Nov 14, 2023

A vulnerability has been identified in COMOS (All versions < V10.4.4). Caching system in the affected application leaks sensitive information such as user and project information…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-7252

Published Nov 3, 2023

bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45321

Published Oct 25, 2023

The Android Client application, when enrolled with the define method 1 (the user manually inserts the server ip address), use HTTP protocol to retrieve sensitive information (ip…

CVSS 8.3 · High
Showing 301-325 of 897 CVEsPage 13 of 36