Skip to main content

CWE archive

CWE-116 CVEs

Programmatic archive

475 CVEs tagged with CWE-11664 Critical, 155 High, 215 Medium, 41 Low, 0 Unrated.

CVE-2021-32067

Published Aug 13, 2021

The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to view sensitive system information through an HTTP response due to insufficient output…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30589

Published Aug 3, 2021

Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a crafted click-to-ca…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32812

Published Aug 2, 2021

Monkshu is an enterprise application server for mobile apps (iOS and Android), responsive HTML 5 apps, and JSON API services. In version 2.90 and earlier, there is a reflected cro…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-34630

Published Jul 30, 2021

In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_UR…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32796

Published Jul 27, 2021

xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape spec…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20333

Published Jul 23, 2021

Sending specially crafted commands to a MongoDB Server may result in artificial log entries being generated or for log entries to be split. This issue affects MongoDB Server v3.6…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-30640

Published Jul 12, 2021

A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the…

CVSS 6.5 · Medium

CVE-2021-23205

Published Jun 11, 2021

Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other hardware items beyond their p…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20195

Published May 28, 2021

A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to user-supplied data fields not…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-4850

Published May 20, 2021

IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote attacker to obtain sensitive information, caused by the leftover files after configuratio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28940

Published Apr 2, 2021

Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to add a extra command to the curl binary. This creates an is…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-26283

Published Mar 24, 2021

go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, control characters are not escaped…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29023

Published Feb 16, 2021

Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary comman…

CVSS 3.5 · Low

CVE-2021-20405

Published Feb 11, 2021

IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to improper encoding of output. IBM X-Force ID: 196183.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13654

Published Dec 31, 2020

XWiki Platform before 12.8 mishandles escaping in the property displayer.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28954

Published Nov 19, 2020

web/controllers/ApiController.groovy in BigBlueButton before 2.2.29 lacks certain parameter sanitization, as demonstrated by accepting control characters in a user name.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26226

Published Nov 18, 2020

In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters tha…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-27604

Published Oct 21, 2020

BigBlueButton before 2.3 does not implement LibreOffice sandboxing. This might make it easier for remote authenticated users to read the API shared secret in the bigbluebutton.pro…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4326

Published Oct 6, 2020

"HCL AppScan Enterprise security rules update administration section of the web application console is missing HTTP Strict-Transport-Security Header."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 401-425 of 475 CVEsPage 17 of 19