Skip to main content

CWE archive

CWE-326 CVEs

Programmatic archive

460 CVEs tagged with CWE-32649 Critical, 191 High, 198 Medium, 22 Low, 0 Unrated.

CVE-2023-32414

Published Jun 23, 2023

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.4. An app may be able to break out of its sandbox.

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33283

Published Jun 7, 2023

Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains access to encrypted secrets can decrypt them by using this key.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29549

Published Jun 2, 2023

Under certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implem…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-23597

Published Jun 2, 2023

A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the `file://` context. Given a reliable exploi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33982

Published May 24, 2023

Bramble Handshake Protocol (BHP) in Briar before 1.5.3 is not forward secure: eavesdroppers can decrypt network traffic between two accounts if they later compromise both accounts…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31135

Published May 17, 2023

Dgraph is an open source distributed GraphQL database. Existing Dgraph audit logs are vulnerable to brute force attacks due to nonce collisions. The first 12 bytes come from a bas…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-21109

Published May 15, 2023

In multiple places of AccessibilityService, there is a possible way to hide the app from the user due to a logic error in the code. This could lead to local escalation of privileg…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-4048

Published May 15, 2023

Inadequate Encryption Strength in CODESYS Development System V3 versions prior to V3.5.18.40 allows an unauthenticated local attacker to access and manipulate code of the encrypte…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2443

Published May 11, 2023

Rockwell Automation ThinManager product allows the use of medium strength ciphers.  If the client requests an insecure cipher, a malicious actor could potentially decrypt traffic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30351

Published May 10, 2023

Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerabil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-2197

Published May 1, 2023

HashiCorp Vault Enterprise 1.13.0 up to 1.13.1 is vulnerable to a padding oracle attack when using an HSM in conjunction with the CKM_AES_CBC_PAD or CKM_AES_CBC encryption mechani…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-28124

Published Apr 19, 2023

Improper usage of symmetric encryption in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow users with access to UI Desktop configuration files to decrypt their c…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27987

Published Apr 10, 2023

In Apache Linkis <=1.3.1, due to the default token generated by Linkis Gateway deployment being too simple, it is easy for attackers to obtain the default token for the attack. Ge…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-23911

Published Mar 10, 2023

An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-45141

Published Mar 6, 2023

Since the Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability was disclosed by Microsoft on Nov 8 2022 and per RFC8429 it is assumed that rc4-hmac is weak, Vulnerable S…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-21444

Published Feb 9, 2023

Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 460 CVEsPage 7 of 19