Skip to main content

CWE archive

CWE-922 CVEs

Programmatic archive

373 CVEs tagged with CWE-92216 Critical, 84 High, 220 Medium, 53 Low, 0 Unrated.

CVE-2021-0639

Published Aug 17, 2021

In multiple functions of libl3oemcrypto.cpp, there is a possible weakness in the existing obfuscation mechanism due to the way sensitive data is handled. This could lead to local…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36786

Published Aug 13, 2021

The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credentials and private keys.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36127

Published Jul 2, 2021

An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalUserRights page provided search results which, for a suppressed MediaWiki user, w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22914

Published Jun 16, 2021

Citrix Cloud Connector before 6.31.0.62192 suffers from insecure storage of sensitive information due to sensitive information being stored in the Citrix Cloud Connector installat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25406

Published Jun 11, 2021

Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device information.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25402

Published Jun 11, 2021

Information Exposure vulnerability in Samsung Notes prior to version 4.2.04.27 allows attacker to access s pen latency information.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-20396

Published Jun 11, 2021

IBM QRadar Analyst Workflow App 1.0 through 1.18.0 for IBM QRadar SIEM allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 19600…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-5008

Published Jun 7, 2021

IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 and 2018.4.1.0 through 2018.4.1.14 stores sensitive information in GET request parameters. This may lead to information disclosure…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-28911

Published May 24, 2021

Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-20391

Published May 14, 2021

IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 195999.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-28653

Published Mar 19, 2021

The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They choose a non-preferred storage mechanism if the device has…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25776

Published Feb 3, 2021

In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29603

Published Jan 29, 2021

In manage_proj_edit_page.php in MantisBT before 2.24.4, any unprivileged logged-in user can retrieve Private Projects' names via the manage_proj_edit_page.php project_id parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-4871

Published Jan 19, 2021

IBM Planning Analytics 2.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 190834.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 373 CVEsPage 13 of 15