Skip to main content

CWE archive

CWE-347 CVEs

Programmatic archive

735 CVEs tagged with CWE-347131 Critical, 313 High, 262 Medium, 28 Low, 1 Unrated.

CVE-2023-50714

Published Dec 22, 2023

yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth2 PKCE…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41337

Published Dec 12, 2023

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. In version 2.3.0-beta2 and prior, when h2o is configured to listen to multiple addresses or ports with each of…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49079

Published Nov 29, 2023

Misskey is an open source, decentralized social media platform. Misskey's missing signature validation allows arbitrary users to impersonate any remote user. This issue has been p…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-47122

Published Nov 10, 2023

Gitsign is software for keyless Git signing using Sigstore. In versions of gitsign starting with 0.6.0 and prior to 0.8.0, Rekor public keys were fetched via the Rekor API, instea…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28804

Published Oct 23, 2023

An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects Linux Client Connector: before…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28796

Published Oct 23, 2023

Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: b…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-46324

Published Oct 23, 2023

pkg/suci/suci.go in free5GC udm before 1.2.0, when Go before 1.19 is used, allows an Invalid Curve Attack because it may compute a shared secret via an uncompressed public key tha…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25333

Published Oct 19, 2023

The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented in mask ROM when loading a module through the SK_LOAD routi…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-43660

Published Sep 27, 2023

Warpgate is a smart SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. The SSH key verification for a user can be bypassed by sending an SSH key of…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42806

Published Sep 21, 2023

Hydra is the layer-two scalability solution for Cardano. Prior to version 0.13.0, not signing and verifying `$\mathsf{cid}$` allows an attacker (which must be a participant of thi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20135

Published Sep 13, 2023

A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. Th…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40727

Published Sep 12, 2023

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application uses weak outdated application signing mechanism.…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 351-375 of 735 CVEsPage 15 of 30