Skip to main content

CWE archive

CWE-203 CVEs

Programmatic archive

747 CVEs tagged with CWE-20316 Critical, 107 High, 538 Medium, 86 Low, 0 Unrated.

CVE-2024-41880

Published Jul 22, 2024

In veilid-core in Veilid before 0.3.4, the protocol's ping function can be misused in a way that decreases the effectiveness of safety and private routes.

CVSS 5.3 · Medium

CVE-2024-39830

Published Jul 3, 2024

Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time comparison for remote cluster to…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39891

Published Jul 2, 2024

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploite…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2022-48730

Published Jun 20, 2024

In the Linux kernel, the following vulnerability has been resolved: dma-buf: heaps: Fix potential spectre v1 gadget It appears like nr could be a Spectre v1 gadget as it's suppl…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6129

Published Jun 18, 2024

A vulnerability, which was classified as problematic, was found in spa-cartcms 1.9.0.6. Affected is an unknown function of the file /login of the component Username Handler. The m…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6056

Published Jun 17, 2024

A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /forgot-pas…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38465

Published Jun 16, 2024

Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31870

Published Jun 15, 2024

IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without having authority to the rela…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-32926

Published Jun 13, 2024

there is a possible information disclosure due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges need…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5697

Published Jun 11, 2024

A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37880

Published Jun 10, 2024

The Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a timing side channel that allows attackers…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-2408

Published Jun 9, 2024

The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an O…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31878

Published Jun 7, 2024

IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. This vulnerability can be used by a malicious actor to gather…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5124

Published Jun 6, 2024

A timing attack vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, specifically within the password comparison logic. The vulnerability is present in version 20240…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30312

Published May 28, 2024

An issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off-path attackers to hijack TCP sessions, which could lead to a denial of service, impersonating the…

CVSS 7.3 · High

CVE-2023-30308

Published May 28, 2024

An issue discovered in Ruijie EG210G-P, Ruijie EG105G-V2, Ruijie NBR, and Ruijie EG105G routers allows attackers to hijack TCP sessions which could lead to a denial of service.

CVSS 6.5 · Medium

CVE-2021-47226

Published May 21, 2024

In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Invalidate FPU state after a failed XRSTOR from a user buffer Both Intel and AMD consider it to be a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30171

Published May 14, 2024

An issue was discovered in Bouncy Castle Java TLS API and JSSE Provider before 1.78. Timing-based leakage may occur in RSA based handshakes because of exception processing.

CVSS 5.9 · Medium

CVE-2024-27839

Published May 14, 2024

A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicious application may be able to determine…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-27283

Published May 4, 2024

IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 747 CVEsPage 8 of 30