Skip to main content

CWE archive

CWE-311 CVEs

Programmatic archive

511 CVEs tagged with CWE-31128 Critical, 269 High, 192 Medium, 22 Low, 0 Unrated.

CVE-2024-29151

Published Mar 18, 2024

Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.

CVSS 9.1 · Critical

CVE-2024-25631

Published Feb 20, 2024

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encrypti…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25630

Published Feb 20, 2024

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the default configuration) an…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24768

Published Feb 5, 2024

1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure keyword, which may cause the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50126

Published Jan 11, 2024

Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned tag via brief physical proximity to one of the original tags,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46219

Published Dec 12, 2023

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33228

Published Nov 1, 2023

The SolarWinds Network Configuration Manager was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users with administrative access to…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41096

Published Oct 26, 2023

Missing Encryption of Security Keys vulnerability in Silicon Labs Ember ZNet SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41095

Published Oct 26, 2023

Missing Encryption of Security Keys vulnerability in Silicon Labs OpenThread SDK on 32 bit, ARM (SecureVault High modules) allows potential modification or extraction of network c…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23371

Published Oct 6, 2023

A cleartext transmission of sensitive information vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local authenticated adm…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43618

Published Sep 20, 2023

An issue was discovered in Croc through 9.6.5. The protocol requires a sender to provide its local IP addresses in cleartext via an ips? message.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22405

Published Sep 8, 2023

IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could e…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 511 CVEsPage 4 of 21