Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

727 CVEs tagged with CWE-66868 Critical, 237 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2022-25643

Published Feb 24, 2022

seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when installed setuid root. The attack vector is a user-supplied socket pathname.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-42712

Published Feb 15, 2022

Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24975

Published Feb 11, 2022

The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13670

Published Feb 11, 2022

Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file that they do not have access…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-45402

Published Feb 11, 2022

The check_alu_op() function in kernel/bpf/verifier.c in the Linux kernel through v5.16-rc5 did not properly update bounds while handling the mov32 instruction, which allows local…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-46354

Published Feb 9, 2022

Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42641

Published Feb 2, 2022

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to discl…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-42640

Published Feb 2, 2022

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reass…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-24868

Published Feb 1, 2022

The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitra…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24775

Published Feb 1, 2022

The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0334

Published Jan 25, 2022

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22154

Published Jan 19, 2022

In a Junos Fusion scenario an External Control of Critical State Data vulnerability in the Satellite Device (SD) control state machine of Juniper Networks Junos OS allows an attac…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-44049

Published Jan 15, 2022

CyberArk Endpoint Privilege Manager (EPM) through 11.5.3.328 before 2021-12-20 allows a local user to gain elevated privileges via a Trojan horse Procmon64.exe in the user's Temp…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39628

Published Jan 14, 2022

In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due to a logic error in the code. This could lead to local information disclosure with…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-23118

Published Jan 12, 2022

Jenkins Debian Package Builder Plugin 1.6.11 and earlier implements functionality that allows agents to invoke command-line `git` at an attacker-specified path on the controller,…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42749

Published Jan 10, 2022

In Beaver Themer, attackers can bypass conditional logic controls (for hiding content) when viewing the post archives. Exploitation requires that a Themer layout is applied to the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39971

Published Jan 3, 2022

Password vault has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability could compromise confidentiality.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37112

Published Jan 3, 2022

Hisuite module has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability may lead to Firmware leak.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 426-450 of 727 CVEsPage 18 of 30