Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

727 CVEs tagged with CWE-66868 Critical, 237 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2022-3952

Published Nov 11, 2022

A vulnerability has been found in ManyDesigns Portofino 5.3.2 and classified as problematic. Affected by this vulnerability is the function createTempDir of the file WarFileLaunch…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-41874

Published Nov 10, 2022

Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri is vulnerable to an Incorrectly-Resolved Name. Due to incor…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-3866

Published Nov 10, 2022

HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2882

Published Oct 28, 2022

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39349

Published Oct 25, 2022

The Tasks.org Android app is an open-source app for to-do lists and reminders. The Tasks.org app uses the activity `ShareLinkActivity.kt` to handle "share" intents coming from oth…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4253

Published Oct 19, 2022

The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39309

Published Oct 14, 2022

GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 le…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39871

Published Oct 7, 2022

Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcas…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39870

Published Oct 7, 2022

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECE…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39869

Published Oct 7, 2022

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27601

Published Sep 29, 2022

In BigBlueButton before 2.2.7, lockSettingsProps.disablePrivateChat does not apply to already opened chats. This occurs in bigbluebutton-html5/imports/ui/components/chat/service.j…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-23950

Published Sep 21, 2022

In Keylime before 6.3.0, Revocation Notifier uses a fixed /tmp path for UNIX domain socket which can allow unprivileged users a method to prohibit keylime operations.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40234

Published Sep 19, 2022

Versions of IBM Spectrum Protect Plus prior to 10.1.12 (excluding 10.1.12) include the private key information for a certificate inside the generated .crt file when uploading a TL…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2403

Published Sep 1, 2022

A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1902

Published Sep 1, 2022

A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes. Notifier secrets were not properly sanitized in the GraphQL API. This flaw allows authenticated ACS users…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2610

Published Aug 12, 2022

Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-0734

Published Aug 11, 2022

In Settings, there is a possible way to determine whether an app is installed without query permissions, due to side channel information disclosure. This could lead to local infor…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 727 CVEsPage 14 of 30