Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

727 CVEs tagged with CWE-66868 Critical, 237 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2023-26458

Published Apr 11, 2023

An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows an authenticated SAP Landscape Management user to obtain pr…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29192

Published Apr 10, 2023

SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for games uploaded by other developers. This has been fixed in ve…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-1777

Published Mar 31, 2023

Mattermost allows an attacker to request a preview of an existing message when creating a new message via the createPost API call, disclosing the contents of the linked message.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1775

Published Mar 31, 2023

When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_deleted events broadcast to all users, leading to disclosure of s…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-1402

Published Mar 23, 2023

The course participation report required additional checks to prevent roles being displayed which the user did not have access to view.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28433

Published Mar 22, 2023

Minio is a Multi-Cloud Object Storage framework. All users on Windows prior to version RELEASE.2023-03-20T20-16-18Z are impacted. MinIO fails to filter the `\` character, which al…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1562

Published Mar 22, 2023

Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-25802

Published Mar 13, 2023

Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../filename` sequences, such as `…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22892

Published Mar 8, 2023

There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Ze…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-46257

Published Mar 7, 2023

An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added to a GitHub Actions runner group via the API by a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25536

Published Mar 2, 2023

Dell PowerScale OneFS 9.4.0.x contains exposure of sensitive information to an unauthorized actor. A malicious authenticated local user could potentially exploit this vulnerabilit…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25544

Published Mar 1, 2023

Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 251-275 of 727 CVEsPage 11 of 30