Skip to main content

CWE archive

CWE-347 CVEs

Programmatic archive

734 CVEs tagged with CWE-347130 Critical, 313 High, 262 Medium, 28 Low, 1 Unrated.

CVE-2024-24694

Published Apr 9, 2024

Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalation of privilege via…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-52538

Published Apr 8, 2024

Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-52043

Published Apr 3, 2024

An issue in D-Link COVR 1100, 1102, 1103 AC1200 Dual-Band Whole-Home Mesh Wi-Fi System (Hardware Rev B1) truncates Wireless Access Point Passwords (WPA-PSK) allowing an attacker t…

CVSS 8.1 · High

CVE-2024-2307

Published Mar 19, 2024

A flaw was found in osbuild-composer. A condition can be triggered that disables GPG verification for package repositories, which can expose the build phase to a Man-in-the-Middle…

CVSS 6.1 · Medium

CVE-2018-25099

Published Mar 18, 2024

In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.

CVSS 9.8 · Critical

CVE-2024-21491

Published Feb 13, 2024

Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly com…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21917

Published Jan 31, 2024

A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-23680

Published Jan 19, 2024

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2023-2030

Published Jan 12, 2024

An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentiall…

CVSS 3.5 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-20021

Published Jan 12, 2024

In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verificat…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-21669

Published Jan 11, 2024

Hyperledger Aries Cloud Agent Python (ACA-Py) is a foundation for building decentralized identity applications and services running in non-mobile environments. When verifying W3C…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-23436

Published Dec 29, 2023

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-23435

Published Dec 29, 2023

Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwrite the correct system file

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 734 CVEsPage 14 of 30