Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

734 CVEs tagged with CWE-66870 Critical, 242 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2022-27331

Published Apr 27, 2022

An access control issue in Zammad v5.0.3 broadcasts administrative configuration changes to all users who have an active application instance, including settings that should only…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1385

Published Apr 19, 2022

Mattermost 6.4.x and earlier fails to properly invalidate pending email invitations when the action is performed from the system console, which allows accidentally invited users t…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-27817

Published Apr 14, 2022

SWHKD 1.1.5 consumes the keyboard events of unintended users. This could potentially cause an information leak, but is usually a denial of functionality.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24411

Published Apr 12, 2022

Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability. A local attacker with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE could potentially exp…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23163

Published Apr 12, 2022

Dell PowerScale OneFS, 8.2,x, 9.1.0.x, 9.2.1.x, and 9.3.0.x contain a denial of service vulnerability. A local malicious user could potentially exploit this vulnerability, leading…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42255

Published Apr 12, 2022

AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27822

Published Apr 11, 2022

Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27576

Published Apr 11, 2022

Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-27818

Published Apr 7, 2022

SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-26850

Published Apr 6, 2022

When creating or updating credentials for single-user access, Apache NiFi wrote a copy of the Login Identity Providers configuration to the operating system temporary directory. O…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21947

Published Apr 1, 2022

A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API (steve) to carry out arbitrar…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-27772

Published Mar 30, 2022

spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.Abstract…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39777

Published Mar 30, 2022

In Telephony, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22572

Published Mar 29, 2022

On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File.createTempFile creates files in the the system temporary di…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28160

Published Mar 29, 2022

Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on the Jenkins controller.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21718

Published Mar 22, 2022

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`,…

CVSS 3.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-25481

Published Mar 21, 2022

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE:…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24074

Published Mar 17, 2022

Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itself that could lead to controlling Wha…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 401-425 of 734 CVEsPage 17 of 30