Skip to main content

CWE archive

CWE-290 CVEs

Programmatic archive

661 CVEs tagged with CWE-290113 Critical, 213 High, 309 Medium, 26 Low, 0 Unrated.

CVE-2022-32983

Published Jun 20, 2022

Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit forwarding actions by filters.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29165

Published May 20, 2022

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. A critical vulnerability has been discovered in Argo CD starting with version 1.4.0 and prior to versions…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-29218

Published May 13, 2022

RubyGems is a package registry used to supply software for the Ruby language ecosystem. An ordering mistake in the code that accepts gem uploads allowed some gems (with platforms…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24858

Published Apr 19, 2022

next-auth v3 users before version 3.29.2 are impacted. next-auth version 4 users before version 4.3.2 are also impacted. Upgrading to 3.29.2 or 4.3.2 will patch this vulnerability…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-21142

Published Feb 24, 2022

Authentication bypass vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.74, Ver.2.9.x series versions prior to Ver.2.9.39, Ver.2.10.x series versions prior to…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24112

Published Feb 11, 2022

An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vuln…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
54.1
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2022-23131

Published Jan 13, 2022

In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
50.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-43807

Published Dec 14, 2021

Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast versions prior to 9.10 allow HTTP method spoofing, allowing to change the assumed HTTP method…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41130

Published Oct 7, 2021

Extensible Service Proxy, a.k.a. ESP is a proxy which enables API management capabilities for JSON/REST or gRPC API services. ESPv1 can be configured to authenticate a JWT token.…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-19003

Published Oct 6, 2021

An issue in Gate One 1.2.0 allows attackers to bypass to the verification check done by the origins list and connect to Gate One instances used by hosts not on the origins list.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40824

Published Sep 13, 2021

A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2 allows a malicious Matrix hom…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40823

Published Sep 13, 2021

A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 526-550 of 661 CVEsPage 22 of 27