Skip to main content

CWE archive

CWE-668 CVEs

Programmatic archive

734 CVEs tagged with CWE-66870 Critical, 242 High, 365 Medium, 56 Low, 1 Unrated.

CVE-2023-42551

Published Nov 7, 2023

Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary file with S…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42549

Published Nov 7, 2023

Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42547

Published Nov 7, 2023

Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitrary…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42546

Published Nov 7, 2023

Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allows attackers to access arbitra…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4910

Published Nov 6, 2023

A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back button in the browser, the tokens page is rendered from the bro…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38994

Published Oct 31, 2023

The 'check_univention_joinstatus' prometheus monitoring script (and other scripts) in UCS 5.0-5 revealed the LDAP plaintext password of the machine account in the process list all…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37911

Published Oct 25, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 9.4-rc-1 and prior to versions 14.10.8 and 15.3-rc-1,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45911

Published Oct 18, 2023

An issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user without a password.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-45357

Published Oct 17, 2023

Archer Platform 6.x before 6.13 P2 HF2 (6.13.0.2.2) contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensiti…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44394

Published Oct 16, 2023

MantisBT is an open source bug tracker. Due to insufficient access-level checks on the Wiki redirection page, any user can reveal private Projects' names, by accessing wiki.php wi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42792

Published Oct 14, 2023

Apache Airflow, in versions prior to 2.7.2, contains a security vulnerability that allows an authenticated user with limited access to some DAGs, to craft a request that could giv…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32275

Published Oct 12, 2023

An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.9674. Specially crafted network packets can lead to a discl…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44102

Published Oct 11, 2023

Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cause the Bluetooth function to be unavailable.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44101

Published Oct 11, 2023

The Bluetooth module has a vulnerability in permission control for broadcast notifications.Successful exploitation of this vulnerability may affect confidentiality.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-44124

Published Sep 27, 2023

The vulnerability is to theft of arbitrary files with system privilege in the Screen recording ("com.lge.gametools.gamerecorder") app in the "com/lge/gametools/gamerecorder/settin…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 734 CVEsPage 7 of 30