Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

727 CVEs tagged with CWE-66868 Critical, 237 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2022-28226

Published Jun 15, 2022

Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges throug…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29247

Published Jun 13, 2022

Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, a…

CVSS 2.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-31649

Published Jun 9, 2022

ownCloud owncloud/core before 10.10.0 Improperly Removes Sensitive Information Before Storage or Transfer.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36710

Published Jun 8, 2022

ToaruOS 1.99.2 is affected by incorrect access control via the kernel. Improper MMU management and having a low GDT address allows it to be mapped in userland. A call gate can the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30734

Published Jun 7, 2022

Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30732

Published Jun 7, 2022

Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access sensitive information via onActivityResult.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30728

Published Jun 7, 2022

Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-30714

Published Jun 7, 2022

Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-28794

Published Jun 7, 2022

Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information.

CVSS 2.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-36532

Published Jun 7, 2022

A vulnerability has been found in Klapp App and classified as problematic. This vulnerability affects unknown code of the component Authorization. The manipulation leads to inform…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28924

Published May 18, 2022

An information disclosure vulnerability in UniverSIS-Students before v1.5.0 allows attackers to obtain sensitive information via a crafted GET request to the endpoint /api/student…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43066

Published May 11, 2022

A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below, version 6.2.9 and below, version 6.0.10 and below allows a…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27331

Published Apr 27, 2022

An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1385

Published Apr 19, 2022

Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users t…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-27817

Published Apr 14, 2022

SWHKD 1.1.5 consumes the keyboard events of unintended users. This could potentially cause an information leak, but is usually a denial of functionality.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24411

Published Apr 12, 2022

Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability. A local attacker with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE could potentially exp…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23163

Published Apr 12, 2022

Dell PowerScale OneFS, 8.2,x, 9.1.0.x, 9.2.1.x, and 9.3.0.x contain a denial of service vulnerability. A local malicious user could potentially exploit this vulnerability, leading…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 727 CVEsPage 16 of 30