Skip to main content

CWE archive

CWE-922 CVEs

Programmatic archive

376 CVEs tagged with CWE-92216 Critical, 84 High, 223 Medium, 53 Low, 0 Unrated.

CVE-2024-5288

Published Aug 27, 2024

An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in sig…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7569

Published Aug 13, 2024

An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-40832

Published Jul 29, 2024

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to view a contact's phone number in system logs.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-6916

Published Jul 19, 2024

A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29120

Published Jul 17, 2024

In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use thi…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38496

Published Jul 15, 2024

The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships.

CVSS 5.1 · Medium

CVE-2024-34721

Published Jul 9, 2024

In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information di…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-38453

Published Jul 3, 2024

The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.

CVSS 7.5 · High

CVE-2024-5598

Published Jun 29, 2024

The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39459

Published Jun 26, 2024

In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file sys…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29953

Published Jun 26, 2024

A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. Th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35526

Published Jun 25, 2024

An issue in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to access sensitive information in the /facade directory.

CVSS 5.9 · Medium

CVE-2024-6295

Published Jun 25, 2024

udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Andro…

CVSS 3.9 · Low

CVE-2024-37654

Published Jun 21, 2024

An issue in BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, AV-02FDR, AV-03D, AV-03BD, AV-04AFD, AV-04ASD, A…

CVSS 6.1 · Medium

CVE-2024-38312

Published Jun 13, 2024

When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This v…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23445

Published Jun 12, 2024

It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api-key.html#security-api-create-…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3723

Published Jun 11, 2024

The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.2 via the wp-content/uploads/advanced…

CVSS 5.3 · Medium

CVE-2024-31404

Published Jun 11, 2024

Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user who can log in to the product to view the data of Scheduler.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31400

Published Jun 11, 2024

Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left in forwarded mail.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6748

Published Jun 11, 2024

The Custom Field Template plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the 'cft' shortcode. This makes it p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 376 CVEsPage 7 of 16