Skip to main content

CWE archive

CWE-345 CVEs

Programmatic archive

650 CVEs tagged with CWE-34583 Critical, 259 High, 266 Medium, 42 Low, 0 Unrated.

CVE-2023-6236

Published Apr 10, 2024

A flaw was found in Red Hat Enterprise Application Platform 8. When an OIDC app that serves multiple tenants attempts to access the second tenant, it should prompt the user to log…

CVSS 7.3 · High

CVE-2023-52546

Published Apr 8, 2024

Vulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30250

Published Apr 4, 2024

Astro-Shield is an integration to enhance website security with SubResource Integrity hashes, Content-Security-Policy headers, and other techniques. Versions from 1.2.0 to 1.3.1 o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35764

Published Apr 3, 2024

Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2384

Published Mar 20, 2024

The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the…

CVSS 4.3 · Medium

CVE-2024-28251

Published Mar 14, 2024

Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's datadocs functionality works by using a Websocket Server. The…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1321

Published Mar 13, 2024

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 3.4.2. This is due to the plugin…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27305

Published Mar 12, 2024

aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP smuggling. SMTP smuggling is a novel vulnerability based on n…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1554

Published Feb 20, 2024

The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24557

Published Feb 1, 2024

Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scrat…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52109

Published Jan 16, 2024

Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-51655

Published Dec 21, 2023

In JetBrains IntelliJ IDEA before 2023.3.2 code execution was possible in Untrusted Project mode via a malicious plugin repository specified in the project configuration

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45292

Published Dec 11, 2023

When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44402

Published Dec 1, 2023

Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. This only impacts apps that have the `embeddedAsarIntegrityVal…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48238

Published Nov 17, 2023

joaquimserafim/json-web-token is a javascript library use to interact with JSON Web Tokens (JWT) which are a compact URL-safe means of representing claims to be transferred betwee…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47631

Published Nov 14, 2023

vantage6 is a framework to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). In affected versions a node does not ch…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47630

Published Nov 14, 2023

Kyverno is a policy engine designed for Kubernetes. An issue was found in Kyverno that allowed an attacker to control the digest of images used by Kyverno users. The issue would r…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 276-300 of 650 CVEsPage 12 of 26