Skip to main content

CWE archive

CWE-345 CVEs

Programmatic archive

650 CVEs tagged with CWE-34583 Critical, 259 High, 266 Medium, 42 Low, 0 Unrated.

CVE-2023-46445

Published Nov 14, 2023

An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-42816

Published Nov 13, 2023

Kyverno is a policy engine designed for Kubernetes. A security vulnerability was found in Kyverno where an attacker could cause denial of service of Kyverno. The vulnerability was…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41898

Published Oct 19, 2023

Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is vulnerable to arbitrary URL loading in a WebView. This ena…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-43800

Published Oct 18, 2023

Arduino Create Agent is a package to help manage Arduino development. The vulnerability affects the endpoint `/v2/pkgs/tools/installed`. A user who has the ability to perform HTTP…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38552

Published Oct 18, 2023

When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43666

Published Oct 16, 2023

Insufficient Verification of Data Authenticity vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0,  General user can view all user data lik…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42782

Published Oct 10, 2023

A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39347

Published Sep 27, 2023

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability to update pod labels can cause Cilium to apply incorrect ne…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8371

Published Sep 21, 2023

Composer before 2016-02-10 allows cache poisoning from other projects built on the same host. This results in attacker-controlled code entering a server-side build process. The is…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43636

Published Sep 20, 2023

In EVE OS, the “measured boot” mechanism prevents a compromised device from accessing the encrypted data located in the vault. As per the “measured boot” design, the PCR values c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26141

Published Sep 14, 2023

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vul…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4589

Published Sep 6, 2023

Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10.9.000002 version. An attacker with an administrator account could perform softwar…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-35719

Published Sep 6, 2023

ManageEngine ADSelfService Plus GINA Client Insufficient Verification of Data Authenticity Authentication Bypass Vulnerability. This vulnerability allows physically present attack…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41045

Published Aug 31, 2023

Graylog is a free and open log management platform. Graylog makes use of only one single source port for DNS queries. Graylog binds a single socket for outgoing DNS queries and wh…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-38831

Published Aug 23, 2023

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may in…

CVSS 7.8 · High
evidence mentions
24
Buzz score
76.0
KEV listedPublic PoC observed
Vendor/product tagsBeta · best-effort
Showing 301-325 of 650 CVEsPage 13 of 26