Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,612 CVEs tagged with CWE-284701 Critical, 1,857 High, 2,521 Medium, 519 Low, 14 Unrated.

CVE-2022-33757

Published Oct 25, 2022

An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This may lead to the disclosure of informati…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-1066

Published Oct 21, 2022

Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-23241

Published Oct 19, 2022

Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerability which could allow an authenticated remote attacker to…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40798

Published Oct 19, 2022

OcoMon 4.0RC1 is vulnerable to Incorrect Access Control. Through a request the user can obtain the real email, sending the same request with correct email its possible to account…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39421

Published Oct 18, 2022

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Easily exploitable vulnerab…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39405

Published Oct 18, 2022

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). The supported version that is affected is 12.2.1.3.0. Easily exp…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3382

Published Oct 17, 2022

HIWIN Robot System Software version 3.3.21.9869 does not properly address the terminated command source. As a result, an attacker could craft code to disconnect HRSS and the contr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3325

Published Oct 17, 2022

Improper access control in the GitLab CE/EE API affecting all versions starting from 12.8 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-3286

Published Oct 17, 2022

Lack of IP address checking in GitLab EE affecting all versions from 14.2 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows a group member to bypass IP restri…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3067

Published Oct 17, 2022

An issue has been discovered in the Import functionality of GitLab CE/EE affecting all versions starting from 14.4 before 15.2.5, all versions starting from 15.3 before 15.3.4, al…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3066

Published Oct 17, 2022

An issue has been discovered in GitLab affecting all versions starting from 10.0 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 befo…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3030

Published Oct 17, 2022

An improper access control issue in GitLab CE/EE affecting all versions starting before 15.1.6, all versions from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows d…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2630

Published Oct 17, 2022

An improper access control issue in GitLab CE/EE affecting all versions starting from 15.2 before 15.2.4, all versions from 15.3 before 15.3.2 allows disclosure of confidential in…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,951-3,975 of 5,612 CVEsPage 159 of 225