Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

727 CVEs tagged with CWE-66868 Critical, 237 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2022-1875

Published Jul 27, 2022

Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1873

Published Jul 27, 2022

Insufficient policy enforcement in COOP in Google Chrome prior to 102.0.5005.61 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1637

Published Jul 26, 2022

Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-1501

Published Jul 26, 2022

Inappropriate implementation in iframe in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1498

Published Jul 26, 2022

Inappropriate implementation in HTML Parser in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1488

Published Jul 26, 2022

Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4951.41 allowed an attacker who convinced a user to install a malicious extension to leak cross-orig…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1137

Published Jul 23, 2022

Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an attacker who convinced a user to install a malicious extension to leak potentially se…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32249

Published Jul 12, 2022

Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gain access to highly sensitive informati…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-33700

Published Jul 12, 2022

Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-33699

Published Jul 12, 2022

Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-33698

Published Jul 12, 2022

Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-33696

Published Jul 12, 2022

Exposure of Sensitive Information in Telephony service prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33694

Published Jul 12, 2022

Exposure of Sensitive Information in CSC application prior to SMR Jul-2022 Release 1 allows local attacker to access wifi information via unprotected intent broadcasting.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33692

Published Jul 12, 2022

Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24139

Published Jul 6, 2022

In IOBit Advanced System Care (AscService.exe) 15, an attacker with SEImpersonatePrivilege can create a named pipe with the same name as one of ASCService's named pipes. ASCServic…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-46687

Published Jul 6, 2022

JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Administrator REST API. This issue affects: JFrog JFrog Artifac…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4561

Published Jun 30, 2022

In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-32530

Published Jun 24, 2022

A CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms, showing the wrong server connection option or the wrong con…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25459

Published Jun 16, 2022

An issue was discovered in function sync_tree in hetero_decision_tree_guest.py in WeBank FATE (Federated AI Technology Enabler) 0.1 through 1.4.2 allows attackers to read sensitiv…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 351-375 of 727 CVEsPage 15 of 30