Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

727 CVEs tagged with CWE-66868 Critical, 237 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2020-20948

Published Dec 27, 2021

An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45708

Published Dec 27, 2021

An issue was discovered in the abomonation crate through 2021-10-17 for Rust. Because transmute operations are insufficiently constrained, there can be an information leak or ASLR…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8702

Published Dec 23, 2021

This issue was addressed with a new entitlement. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra, iOS 12.4, tvOS…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35215

Published Dec 16, 2021

An issue in Atomix v3.1.5 allows attackers to access sensitive information when a malicious Atomix node queries distributed variable primitives which contain the entire primitive…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41065

Published Dec 14, 2021

An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wait for a privileged user to open a session on the Listary i…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39915

Published Dec 13, 2021

Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions sta…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22568

Published Dec 9, 2021

When using the dart pub publish command to publish a package to a third-party package server, the request would be authenticated with an oauth2 access_token that is valid for publ…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25515

Published Dec 8, 2021

An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29115

Published Dec 7, 2021

An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23264

Published Dec 2, 2021

Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23263

Published Dec 2, 2021

Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary).

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38004

Published Nov 23, 2021

Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36319

Published Nov 20, 2021

Dell Networking OS10 versions 10.4.3.x, 10.5.0.x and 10.5.1.x contain an information exposure vulnerability. A low privileged authenticated malicious user can gain access to SNMP…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort
Showing 451-475 of 727 CVEsPage 19 of 30