Skip to main content

CWE archive

CWE-326 CVEs

Programmatic archive

455 CVEs tagged with CWE-32649 Critical, 188 High, 196 Medium, 22 Low, 0 Unrated.

CVE-2023-47364

Published Nov 9, 2023

The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications to victims

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47363

Published Nov 9, 2023

The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44690

Published Oct 19, 2023

Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30132

Published Oct 19, 2023

An issue discovered in IXP Data EasyInstall 6.6.14907.0 allows attackers to gain escalated privileges via static Cryptographic Key.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4129

Published Sep 27, 2023

Dell Data Protection Central, version 19.9, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker could potentially exploit this vulnerabil…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41305

Published Sep 27, 2023

Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidenti…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-46783

Published Aug 28, 2023

An issue was discovered in Stormshield SSL VPN Client before 3.2.0. If multiple address books are used, an attacker may be able to access the other encrypted address book.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-34971

Published Aug 24, 2023

An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to decryp…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-21145

Published Jul 13, 2023

In updatePictureInPictureMode of ActivityRecord.java, there is a possible bypass of background launch restrictions due to a logic error in the code. This could lead to local escal…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-20942

Published Jul 13, 2023

In openMmapStream of AudioFlinger.cpp, there is a possible way to record audio without displaying the microphone privacy indicator due to a logic error in the code. This could lea…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20185

Published Jul 12, 2023

A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to r…

CVSS 7.4 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2023-34337

Published Jul 5, 2023

AMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based message authentication code (HMAC). A successful exploit of this…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37301

Published Jun 30, 2023

An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesn't use EditEntity for undo and restore, the intended interaction with AbuseF…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32414

Published Jun 23, 2023

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.4. An app may be able to break out of its sandbox.

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33283

Published Jun 7, 2023

Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains access to encrypted secrets can decrypt them by using this key.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29549

Published Jun 2, 2023

Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implem…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 126-150 of 455 CVEsPage 6 of 19