Skip to main content

CWE archive

CWE-311 CVEs

Programmatic archive

511 CVEs tagged with CWE-31128 Critical, 269 High, 192 Medium, 22 Low, 0 Unrated.

CVE-2023-40251

Published Aug 17, 2023

Missing Encryption of Sensitive Data vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Man in the Middle…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4384

Published Aug 16, 2023

A vulnerability has been found in MaximaTech Portal Executivo 21.9.1.140 and classified as problematic. This vulnerability affects unknown code of the component Cookie Handler. Th…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-39954

Published Aug 10, 2023

user_oidc provides the OIDC connect user backend for Nextcloud, an open-source cloud platform. Starting in version 1.0.0 and prior to version 1.3.3, an attacker that obtained at l…

CVSS 3.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-38699

Published Aug 4, 2023

MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `verify=False` disables SSL certif…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-38688

Published Aug 4, 2023

twitch-tui provides Twitch chat in a terminal. Prior to version 2.4.1, the connection is not using TLS for communication. In the configuration of the irc connection, the software…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31825

Published Jul 13, 2023

An issue found in Inageya v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Inageya function.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31822

Published Jul 13, 2023

An issue found in Entetsu Store v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Entetsu Store function.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31820

Published Jul 13, 2023

An issue found in Shizutetsu Store v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-31819

Published Jul 13, 2023

An issue found in KEISEI STORE Co, Ltd. LIVRE KEISEI v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37943

Published Jul 12, 2023

Jenkins Active Directory Plugin 2.30 and earlier ignores the "Require TLS" and "StartTls" options and always performs the connection test to Active directory unencrypted, allowing…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37192

Published Jul 7, 2023

Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, potentially allowing them to redirect Bi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34258

Published May 31, 2023

An issue was discovered in BMC Patrol before 22.1.00. The agent's configuration can be remotely queried. This configuration contains the Patrol account password, encrypted with a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28045

Published May 19, 2023

Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with low privileges could potentially exploit this vulnerability,…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32982

Published May 16, 2023

Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier stores extra variables unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with I…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-21404

Published May 8, 2023

AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor ca…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32290

Published May 7, 2023

The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22948

Published Apr 13, 2023

An issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is unsecured read access to an SSH private key. Any code that runs as the tigergraph user is able to read…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 101-125 of 511 CVEsPage 5 of 21