Skip to main content

CWE archive

CWE-346 CVEs

Programmatic archive

627 CVEs tagged with CWE-34664 Critical, 217 High, 324 Medium, 21 Low, 1 Unrated.

CVE-2024-2377

Published Apr 30, 2024

A vulnerability exists in the too permissive HTTP response header web server settings of the SDM600. An attacker can take advantage of this and possibly carry out privileged actio…

CVSS 7.6 · High

CVE-2024-32764

Published Apr 26, 2024

A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege lev…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-1249

Published Apr 17, 2024

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions…

CVSS 7.4 · High

CVE-2024-28224

Published Apr 8, 2024

Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with a large language…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-2447

Published Apr 5, 2024

Mattermost versions 8.1.x before 8.1.11, 9.3.x before 9.3.3, 9.4.x before 9.4.4, and 9.5.x before 9.5.2 fail to authenticate the source of certain types of post actions, allowing…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5973

Published Apr 5, 2024

Brocade Web Interface in Brocade Fabric OS v9.x and before v9.2.0 does not properly represent the portName to the user if the portName contains reserved characters. This could…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-47157

Published Mar 18, 2024

The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling.

CVSS 9.8 · Critical

CVE-2024-2182

Published Mar 12, 2024

A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packe…

CVSS 6.5 · Medium

CVE-2024-25996

Published Mar 12, 2024

An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.

CVSS 5.3 · Medium

CVE-2024-25124

Published Feb 21, 2024

Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application to multiple C…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-26135

Published Feb 20, 2024

MeshCentral is a full computer management web site. Versions prior to 1.1.21 a cross-site websocket hijacking (CSWSH) vulnerability within the control.ashx endpoint. This componen…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-0009

Published Feb 14, 2024

An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a V…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24557

Published Feb 1, 2024

Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scrat…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40547

Published Jan 25, 2024

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to cra…

CVSS 8.3 · High
evidence mentions
5
Buzz score
29.4
Vendor/product tagsBeta · best-effort

CVE-2024-23898

Published Jan 24, 2024

Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint,…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-0814

Published Jan 24, 2024

Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security se…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47200

Published Jan 23, 2024

A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Plea…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47199

Published Jan 23, 2024

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an att…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47198

Published Jan 23, 2024

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an att…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47197

Published Jan 23, 2024

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an att…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47196

Published Jan 23, 2024

An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations. Please note: an att…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 326-350 of 627 CVEsPage 14 of 26