Skip to main content

CWE archive

CWE-922 CVEs

Programmatic archive

373 CVEs tagged with CWE-92216 Critical, 84 High, 220 Medium, 53 Low, 0 Unrated.

CVE-2024-44175

Published Oct 28, 2024

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1. An app may be able to access sensitive user data.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-44174

Published Oct 28, 2024

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An attacker may be able to view restricted content from the lock screen.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30361

Published Oct 25, 2024

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authentication is required. The information disclose…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-30359

Published Oct 25, 2024

OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30122

Published Oct 23, 2024

HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less sec…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32191

Published Oct 16, 2024

When RKE provisions a cluster, it stores the cluster state in a configmap called `full-cluster-state` inside the `kube-system` namespace of the cluster itself. The information ava…

CVSS 9.9 · Critical

CVE-2024-21258

Published Oct 15, 2024

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.14. Easily exploit…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48770

Published Oct 11, 2024

An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update process.

CVSS 8.2 · High

CVE-2024-42018

Published Oct 11, 2024

An issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved from management nodes. These parameters…

CVSS 7.7 · High

CVE-2024-30132

Published Oct 1, 2024

HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-28808

Published Sep 30, 2024

An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-46635

Published Sep 30, 2024

An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOr…

CVSS 5.9 · Medium

CVE-2024-47122

Published Sep 26, 2024

In the goTenna Pro App, the encryption keys are stored along with a static IV on the End User Device (EUD). This allows for complete decryption of keys stored on the EUD if phys…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45374

Published Sep 26, 2024

The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-43694

Published Sep 26, 2024

In the goTenna Pro ATAK Plugin application, the encryption keys are stored along with a static IV on the device. This allows for complete decryption of keys stored on the device…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47197

Published Sep 26, 2024

Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This issue affects Maven Archetype…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39339

Published Sep 18, 2024

A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to information disclosu…

CVSS 7.5 · High

CVE-2024-37728

Published Sep 10, 2024

Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via…

CVSS 7.5 · High
Showing 126-150 of 373 CVEsPage 6 of 15