Skip to main content

CWE archive

CWE-203 CVEs

Programmatic archive

747 CVEs tagged with CWE-20316 Critical, 107 High, 538 Medium, 86 Low, 0 Unrated.

CVE-2024-48644

Published Oct 22, 2024

Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remote attackers to determine valid user acco…

CVSS 5.3 · Medium

CVE-2024-47678

Published Oct 21, 2024

In the Linux kernel, the following vulnerability has been resolved: icmp: change the order of rate limits ICMP messages are ratelimited : After the blamed commits, the two rate…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21251

Published Oct 15, 2024

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Difficult to exploit vulnerabili…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-21233

Published Oct 15, 2024

Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.24, 21.3-21.15 and 23.4-23.5. Easily exploitable…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21210

Published Oct 15, 2024

Vulnerability in Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u421, 8u421-perf, 11.0.24, 17.0.12, 21.0.4 and 23. Difficult to e…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-47869

Published Oct 10, 2024

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **timing attack** in the way Gradio compares hashes for the `analytics_dashbo…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-36325

Published Oct 9, 2024

i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 and IPv6 addresses…

CVSS 3.7 · Low

CVE-2024-45231

Published Oct 8, 2024

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9513

Published Oct 4, 2024

A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this issue is some unknown functionality of the file /controller/a…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47129

Published Sep 26, 2024

The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payload regard…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41715

Published Sep 26, 2024

The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the length of the payloa…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23984

Published Sep 16, 2024

Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

CVSS 6.8 · Medium

CVE-2024-34336

Published Sep 12, 2024

User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45052

Published Sep 4, 2024

Fides is an open-source privacy engineering platform. Prior to version 2.44.0, a timing-based username enumeration vulnerability exists in Fides Webserver authentication. This vul…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1543

Published Aug 29, 2024

The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacker with cache-line resolution. In a controlled environment s…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1544

Published Aug 27, 2024

Generating the ECDSA nonce k samples a random number r and then truncates this randomness with a modular reduction mod n where n is the order of the elliptic curve. Meaning k =…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41952

Published Jul 31, 2024

Zitadel is an open source identity management system. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to gues…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 747 CVEsPage 7 of 30