Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

727 CVEs tagged with CWE-66868 Critical, 237 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2021-41988

Published Jan 26, 2023

Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45438

Published Jan 16, 2023

When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticated user to access dashboard configuration metadata using a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-22497

Published Jan 14, 2023

Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an automatically generated MACHINE GUID. It is generated when…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45935

Published Jan 6, 2023

Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit. Vulnerable components…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0337

Published Jan 2, 2023

Inappropriate implementation in File System API in Google Chrome on Windows prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a craft…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4817

Published Dec 28, 2022

A vulnerability was found in centic9 jgit-cookbook. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to insecure temporary file…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-10004

Published Dec 27, 2022

Token validation methods are susceptible to a timing side-channel during HMAC comparison. With a large enough number of requests over a low latency connection, an attacker may use…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9011

Published Dec 26, 2022

In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid usernames.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45895

Published Dec 25, 2022

Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-38474

Published Dec 22, 2022

A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-38599

Published Dec 8, 2022

Teleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web interface.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32221

Published Dec 5, 2022

When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been…

CVSS 9.8 · Critical

CVE-2022-41971

Published Dec 1, 2022

Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0, guests can continue to receive video streams fro…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1911

Published Nov 30, 2022

Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating syst…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21126

Published Nov 29, 2022

The package com.github.samtools:htsjdk before 3.0.1 are vulnerable to Creation of Temporary File in Directory with Insecure Permissions due to the createTempDir() function in util…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41954

Published Nov 25, 2022

MPXJ is an open source library to read and write project plans from a variety of file formats and databases. On Unix-like operating systems (not Windows or macos), MPXJ's use of `…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 301-325 of 727 CVEsPage 13 of 30