Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

727 CVEs tagged with CWE-66868 Critical, 237 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2021-39212

Published Sep 13, 2021

ImageMagick is free software delivered as a ready-to-run binary distribution or as source code that you may use, copy, modify, and distribute in both open and proprietary applicat…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36002

Published Sep 1, 2021

Adobe Captivate version 11.5.5 (and earlier) is affected by an Creation of Temporary File In Directory With Incorrect Permissions vulnerability that could result in privilege esca…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-18972

Published Aug 25, 2021

Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToeniz…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30921

Published Aug 24, 2021

A logic issue was addressed with improved state management. This issue is fixed in iOS 14.5 and iPadOS 14.5. A user's password may be visible onscreen.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38712

Published Aug 16, 2021

OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to block the access via an NGINX configuration file.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37704

Published Aug 12, 2021

PhpFastCache is a high-performance backend cache system (packagist package phpfastcache/phpfastcache). In versions before 6.1.5, 7.1.2, and 8.0.7 the `phpinfo()` can be exposed if…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22385

Published Aug 10, 2021

A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause Kernel Code E…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-21356

Published Aug 6, 2021

An information disclosure vulnerability in upload.php of PopojiCMS 1.2 leads to physical path disclosure of the host when 'name = "file" is deleted during file uploads.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22420

Published Aug 3, 2021

A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers may exploit this vulnerability to cause the underlying trust…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-32788

Published Jul 27, 2021

Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-0588

Published Jul 14, 2021

In processInboundMessage of MceStateMachine.java, there is a possible SMS disclosure due to a missing permission check. This could lead to local information disclosure with no add…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-22535

Published Jul 9, 2021

Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-24001

Published Jun 24, 2021

A compromised content process could have performed session history manipulations it should not have been able to due to testing infrastructure that was not restricted to testing-o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-18647

Published Jun 22, 2021

Information Disclosure in NoneCMS v1.3 allows remote attackers to obtain sensitive information via the component "/nonecms/vendor".

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 501-525 of 727 CVEsPage 21 of 30