Skip to main content

CWE archive

CWE-319 CVEs

Programmatic archive

897 CVEs tagged with CWE-31982 Critical, 359 High, 402 Medium, 54 Low, 0 Unrated.

CVE-2021-33408

Published May 27, 2021

Local File Inclusion vulnerability in Ab Initio Control>Center before 4.0.2.6 allows remote attackers to retrieve arbitrary files. Fixed in v4.0.2.6 and v4.0.3.1.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25643

Published May 26, 2021

An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrator privileges, @cbq-engine-cbauth and @index-cbauth, le…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27924

Published May 19, 2021

An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies in the logs. This allows for the impersonation of a us…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20564

Published May 14, 2021

IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3003

Published May 10, 2021

Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allows man-in-the-middle attackers to spoof product updates.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27574

Published May 7, 2021

An issue was discovered in Emote Remote Mouse through 4.0.0.0. It uses cleartext HTTP to check, and request, updates. Thus, attackers can machine-in-the-middle a victim to downloa…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27569

Published May 7, 2021

An issue was discovered in Emote Remote Mouse through 4.0.0.0. Attackers can maximize or minimize the window of a running process by sending the process name in a crafted packet.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31671

Published Apr 27, 2021

pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema-first and --schema-only options is mishandled. For example…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3494

Published Apr 26, 2021

A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause a Man-in-the-Middle attack. The FreeIPA module of Foreman s…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26197

Published Apr 20, 2021

Dell PowerScale OneFS 8.1.0 - 9.1.0 contains an LDAP Provider inability to connect over TLSv1.2 vulnerability. It may make it easier to eavesdrop and decrypt such traffic for a ma…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23884

Published Apr 15, 2021

Cleartext Transmission of Sensitive Information vulnerability in the ePO Extension of McAfee Content Security Reporter (CSR) prior to 2.8.0 allows an ePO administrator to view the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7308

Published Apr 15, 2021

Cleartext Transmission of Sensitive Information between McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update and McAfee Global Threat Intelligence (GTI)…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27194

Published Mar 25, 2021

Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows logi…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-21387

Published Mar 19, 2021

Wrongthink peer-to-peer, end-to-end encrypted messenger with PeerJS and Axolotl ratchet. In wrongthink from version 2.0.0 and before 2.3.0 there was a set of vulnerabilities causi…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-35456

Published Mar 17, 2021

The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and media files via logcat because of excessive logging.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3417

Published Mar 9, 2021

An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Administrator (LXCA), if added as a Resource Manager, are encod…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 551-575 of 897 CVEsPage 23 of 36