Skip to main content

CWE archive

CWE-755 CVEs

Programmatic archive

585 CVEs tagged with CWE-75528 Critical, 266 High, 267 Medium, 24 Low, 0 Unrated.

CVE-2023-21408

Published Aug 3, 2023

Due to insufficient file permissions, unprivileged users could gain access to unencrypted user credentials that are used in the integration interface towards 3rd party systems.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33370

Published Aug 3, 2023

An uncaught exception vulnerability exists in Control ID IDSecure 4.7.26.0 and prior, allowing attackers to cause the main web server of IDSecure to fault and crash, causing a den…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3774

Published Jul 28, 2023

An unhandled error in Vault Enterprise's namespace creation may cause the Vault process to crash, potentially resulting in denial of service. Fixed in 1.14.1, 1.13.5, and 1.12.9.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36832

Published Jul 14, 2023

An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series allows an unauthenticated network-based attacker to sen…

CVSS 7.5 · High

CVE-2023-1695

Published Jul 6, 2023

Vulnerability of failures to capture exceptions in the communication framework. Successful exploitation of this vulnerability may cause features to perform abnormally.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36933

Published Jul 5, 2023

In Progress MOVEit Transfer before 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), it is possible for an attacker to invoke a me…

CVSS 7.5 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2023-1732

Published May 10, 2023

When sampling randomness for a shared secret, the implementation of Kyber and FrodoKEM, did not check whether crypto/rand.Read() returns an error. In rare deployment cases (error…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27978

Published Apr 26, 2023

Tooljet v1.6 does not properly handle missing values in the API, allowing attackers to arbitrarily reset passwords via a crafted HTTP request.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38363

Published Apr 20, 2023

An issue was discovered in ONOS 2.5.1. In IntentManager, the install-requested intent (which causes an exception) remains in pendingMap (in memory) forever. Deletion is possible n…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-29520

Published Apr 19, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to break many translations coming from wiki pages by creatin…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28970

Published Apr 17, 2023

An Improper Check or Handling of Exceptional Conditions vulnerability in packet processing on the network interfaces of Juniper Networks Junos OS on JRR200 route reflector applian…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28842

Published Apr 4, 2023

Moby) is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28841

Published Apr 4, 2023

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28840

Published Apr 4, 2023

Moby is an open source container framework developed by Docker Inc. that is distributed as Docker, Mirantis Container Runtime, and various other downstream projects/products. The…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28631

Published Mar 28, 2023

comrak is a CommonMark + GFM compatible Markdown parser and renderer written in rust. A Comrak AST can be constructed manually by a program instead of parsing a Markdown document…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24308

Published Mar 28, 2023

A potential memory vulnerability due to insufficient input validation in PDFXEditCore.x64.dll in PDF-XChange Editor version 9.3 by Tracker Software may allow attackers to execute…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23121

Published Mar 28, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The speci…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
25.6
Vendor/product tagsBeta · best-effort

CVE-2023-20993

Published Mar 24, 2023

In multiple functions of SnoozeHelper.java, there is a possible failure to persist settings due to an uncaught exception. This could lead to local escalation of privilege with no…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28114

Published Mar 22, 2023

`cilium-cli` is the command line interface to install, manage, and troubleshoot Kubernetes clusters running Cilium. Prior to version 0.13.2,`cilium-cli`, when used to configure cl…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 585 CVEsPage 8 of 24