Skip to main content

CWE archive

CWE-345 CVEs

Programmatic archive

685 CVEs tagged with CWE-34588 Critical, 270 High, 282 Medium, 45 Low, 0 Unrated.

CVE-2023-2866

Published Jun 7, 2023

If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2987

Published May 31, 2023

The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in ver…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-28386

Published May 22, 2023

Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware updates correctly. The device only calculates the MD5 hash of the firmware and does not check using a pri…

CVSS 8.6 · High

CVE-2023-32993

Published May 16, 2023

Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier does not perform hostname validation when connecting to miniOrange or the configured IdP to retrieve SAML metadata, which…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4537

Published May 9, 2023

The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-28863

Published Apr 18, 2023

AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-48431

Published Mar 29, 2023

In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmation.

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0350

Published Mar 13, 2023

Akuvox E11 does not ensure that a file extension is associated with the file provided. This could allow an attacker to upload a file to the device by changing the extension of a m…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-20180

Published Mar 6, 2023

A vulnerability classified as critical has been found in Zerocoin libzerocoin. Affected is the function CoinSpend::CoinSpend of the file CoinSpend.cpp of the component Proof Handl…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26481

Published Mar 4, 2023

authentik is an open-source Identity Provider. Due to an insufficient access check, a recovery flow link that is created by an admin (or sent via email by an admin) can be used to…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-21441

Published Feb 9, 2023

Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allow…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23941

Published Feb 3, 2023

SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, Credit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23940

Published Feb 3, 2023

OpenZeppelin Contracts for Cairo is a library for secure smart contract development written in Cairo for StarkNet, a decentralized ZK Rollup. `is_valid_eth_signature` is missing a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46370

Published Jan 12, 2023

Rumpus - FTP server version 9.0.7.1 Improper Token Verification– vulnerability may allow bypassing identity verification.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort
Showing 376-400 of 685 CVEsPage 16 of 28