Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

727 CVEs tagged with CWE-66868 Critical, 237 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2023-24567

Published Mar 1, 2023

Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially explo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26041

Published Feb 27, 2023

Nextcloud Talk is a fully on-premises audio/video and chat communication service. When cron jobs were misconfigured and therefore messages are not expired, the API would still ret…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-23501

Published Feb 27, 2023

The issue was addressed with improved memory handling This issue is fixed in macOS Ventura 13.2. An app may be able to disclose kernel memory.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27265

Published Feb 27, 2023

Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-44310

Published Feb 24, 2023

In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0481

Published Feb 24, 2023

In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that coul…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-39952

Published Feb 16, 2023

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6…

CVSS 9.8 · Critical
evidence mentions
14
Buzz score
46.6
Vendor/product tagsBeta · best-effort

CVE-2023-25192

Published Feb 15, 2023

AMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-update-5.00.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24523

Published Feb 14, 2023

An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted Configu…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-34364

Published Feb 10, 2023

Dell BSAFE SSL-J, versions before 6.5 and version 7.0 contain a debug message revealing unnecessary information vulnerability. This may lead to disclosing sensitive information to…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4903

Published Feb 10, 2023

A vulnerability was found in CodenameOne 7.0.70. It has been classified as problematic. Affected is an unknown function. The manipulation leads to use of implicit intent for sensi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21447

Published Feb 9, 2023

Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit int…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21445

Published Feb 9, 2023

Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21438

Published Feb 9, 2023

Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-46756

Published Feb 1, 2023

Dell VxRail, versions prior to 7.0.410, contain a Container Escape Vulnerability. A local high-privileged attacker could potentially exploit this vulnerability, leading to the exe…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-26329

Published Jan 26, 2023

File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue af…

CVSS 1.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-41989

Published Jan 26, 2023

Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 276-300 of 727 CVEsPage 12 of 30