Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

727 CVEs tagged with CWE-66868 Critical, 237 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2020-12488

Published Nov 10, 2021

The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22047

Published Oct 28, 2021

In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22044

Published Oct 28, 2021

In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign cli…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22468

Published Oct 28, 2021

A component of the HarmonyOS has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability. Local attackers may exploit this vulnerability to cause kernel address…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-22454

Published Oct 28, 2021

A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause core dump.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41140

Published Oct 19, 2021

Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given by user to secure topics and p…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39184

Published Oct 12, 2021

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sa…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40497

Published Oct 12, 2021

SAP BusinessObjects Analysis (edition for OLAP) - versions 420, 430, allows an attacker to exploit certain application endpoints to read sensitive data. These endpoints are normal…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28145

Published Oct 12, 2021

Arbitrary file deletion vulnerability was discovered in wuzhicms v 4.0.1 via coreframe\app\attachment\admin\index.php, which allows attackers to access sensitive information.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-21503

Published Oct 5, 2021

waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=gift&a=a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41094

Published Oct 4, 2021

Wire is an open source secure messenger. Users of Wire by Bund may bypass the mandatory encryption at rest feature by simply disabling their device passcode. Upon launching, the a…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22869

Published Sep 24, 2021

An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner group it should not have had access to. This affects…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-41088

Published Sep 23, 2021

Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's web UI backend (started by `elvish -web`) hosts an endpoint…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14130

Published Sep 16, 2021

Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi community app Affected Version <3.0.210809

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40639

Published Sep 15, 2021

Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-19155

Published Sep 15, 2021

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' funct…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23034

Published Sep 14, 2021

On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, undisclosed requests can cause th…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Showing 476-500 of 727 CVEsPage 20 of 30