Skip to main content

CWE archive

CWE-345 CVEs

Programmatic archive

649 CVEs tagged with CWE-34583 Critical, 258 High, 266 Medium, 42 Low, 0 Unrated.

CVE-2024-7256

Published Aug 1, 2024

Insufficient data validation in Dawn in Google Chrome on Android prior to 127.0.6533.88 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium secu…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-25638

Published Jul 22, 2024

dnsjava is an implementation of DNS in Java. Records in DNS replies are not checked for their relevance to the query, allowing an attacker to respond with RRs from different zones…

CVSS 8.9 · High

CVE-2024-40644

Published Jul 18, 2024

gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited use…

CVSS 6.8 · Medium

CVE-2024-3173

Published Jul 16, 2024

Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to perform OS-level privilege escalation via a malicious file. (Chromium…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37370

Published Jun 28, 2024

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear tru…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-44593

Published Jun 21, 2024

Use of Less Trusted Source vulnerability in SolidWP Solid Security allows HTTP DoS.This issue affects Solid Security: from n/a through 9.3.1.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-5458

Published Jun 9, 2024

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDA…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30162

Published Jun 7, 2024

Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.php IPS\core\modules\admin\editor\_toolbar::addPlugin() metho…

CVSS 7.2 · High

CVE-2024-3049

Published Jun 6, 2024

A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth ser…

CVSS 5.9 · Medium

CVE-2024-2382

Published Jun 4, 2024

The Authorize.net Payment Gateway For WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 8.0. This is due to the plugin not pro…

CVSS 5.3 · Medium

CVE-2024-1718

Published Jun 4, 2024

The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient payment validation in the update_o…

CVSS 5.3 · Medium

CVE-2024-23601

Published May 28, 2024

A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can lead to arbitrary code execution…

CVSS 9.8 · Critical

CVE-2024-31341

Published May 17, 2024

Insufficient Verification of Data Authenticity vulnerability in Cozmoslabs Profile Builder allows Functionality Bypass.This issue affects Profile Builder: from n/a through 3.11.2.

CVSS 5.3 · Medium

CVE-2024-35175

Published May 14, 2024

sshpiper is a reverse proxy for sshd. Starting in version 1.0.50 and prior to version 1.3.0, the way the proxy protocol listener is implemented in sshpiper can allow an attacker t…

CVSS 5.3 · Medium

CVE-2023-45586

Published May 14, 2024

An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, version 7.2.0 through 7.2.7 and befo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-33494

Published May 14, 2024

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.…

CVSS 6.9 · Medium

CVE-2024-34354

Published May 14, 2024

CMSaaSStarter is a SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Any forks of the CMSaaSStarter template before commit 7904d416d2c72ec75f42fbf51e9e64fa74…

CVSS 6.5 · Medium
Showing 251-275 of 649 CVEsPage 11 of 26