Skip to main content

CWE archive

CWE-345 CVEs

Programmatic archive

707 CVEs tagged with CWE-34591 Critical, 278 High, 291 Medium, 47 Low, 0 Unrated.

CVE-2021-3349

Published Feb 1, 2021

GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information fr…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-26547

Published Feb 1, 2021

Monal before 4.9 does not implement proper sender verification on MAM and Message Carbon (XEP-0280) results. This allows a remote attacker (able to send stanzas to a victim) to in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-9141

Published Jan 13, 2021

There is a improper privilege management vulnerability in some Huawei smartphone. Successful exploitation of this vulnerability can cause information disclosure and malfunctions d…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-1677

Published Oct 16, 2020

When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle child elements in SAML responses, allowing a remote attacker to modify a valid SAML re…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26893

Published Oct 16, 2020

An issue was discovered in ClamXAV 3 before 3.1.1. A malicious actor could use a properly signed copy of ClamXAV 2 (running with an injected malicious dylib) to communicate with C…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9230

Published Oct 12, 2020

WS5800-10 version 10.0.3.25 has a denial of service vulnerability. Due to improper verification of specific message, an attacker may exploit this vulnerability to cause specific f…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15222

Published Sep 24, 2020

In ORY Fosite (the security first OAuth2 & OpenID Connect framework for Go) before version 0.31.0, when using "private_key_jwt" authentication the uniqueness of the `jti` value is…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16007

Published Sep 23, 2020

A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an unauthenticated, local attacker to perform a service hijac…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16000

Published Sep 23, 2020

A vulnerability in the automatic update process of Cisco Umbrella Roaming Client for Windows could allow an authenticated, local attacker to install arbitrary, unapproved applicat…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24045

Published Sep 17, 2020

A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the opera…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25019

Published Aug 29, 2020

jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-16250

Published Aug 26, 2020

HashiCorp Vault and Vault Enterprise versions 0.7.1 and newer, when configured with the AWS IAM auth method, may be vulnerable to authentication bypass. Fixed in 1.2.5, 1.3.8, 1.4…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11985

Published Aug 7, 2020

IP address spoofing when proxying using mod_remoteip and mod_rewrite For configurations using proxying with mod_remoteip and certain mod_rewrite rules, an attacker could spoof the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15899

Published Jul 28, 2020

Grin 3.0.0 before 4.0.0 has insufficient validation of data related to Mimblewimble.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15699

Published Jul 15, 2020

An issue was discovered in Joomla! through 3.9.19. Missing validation checks on the usergroups table object can result in a broken site configuration.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12119

Published Jul 2, 2020

Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value of an unconfirmed transaction as soon as it is received (be…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 551-575 of 707 CVEsPage 23 of 29