Skip to main content

CWE archive

CWE-922 CVEs

Programmatic archive

376 CVEs tagged with CWE-92216 Critical, 84 High, 223 Medium, 53 Low, 0 Unrated.

CVE-2024-36788

Published Jun 7, 2024

Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly intercept and access sensitive communications…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-5599

Published Jun 7, 2024

The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.7 via the 'fi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5206

Published Jun 6, 2024

A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in version 1.5.0…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35311

Published May 29, 2024

Yubico YubiKey 5 Series before 5.7.0, Security Key Series before 5.7.0, YubiKey Bio Series before 5.6.4, and YubiKey 5 FIPS before 5.7.2 have Incorrect Access Control.

CVSS 3.3 · Low

CVE-2022-44581

Published May 17, 2024

Insecure Storage of Sensitive Information vulnerability in WPMU DEV Defender Security allows : Screen Temporary Files for Sensitive Information.This issue affects Defender Securit…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4213

Published May 14, 2024

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functiona…

CVSS 5.3 · Medium

CVE-2024-27789

Published May 14, 2024

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS Ventura 13.6.7. An app may b…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-23229

Published May 14, 2024

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS Ventura 13.6.5. A malicious appli…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6962

Published May 2, 2024

The WP Meta SEO plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.12 via the meta description. This makes it possible…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32211

Published May 1, 2024

An issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to obtain sensitive information via the UserClass.cs and Settings.cs components.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3678

Published Apr 26, 2024

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32236

Published Apr 25, 2024

An issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in the index.php component.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-29968

Published Apr 19, 2024

An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances are configured in disaster recovery mode. SQL Table names,…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-29965

Published Apr 19, 2024

In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface ("SSH"). The resulting backups are world…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-21117

Published Apr 16, 2024

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affected are 8.5.6 and 8.5.7. Eas…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30917

Published Apr 11, 2024

An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted history_…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31278

Published Apr 10, 2024

Insertion of Sensitive Information Into Sent Data vulnerability in Leap13 Premium Addons for Elementor premium-addons-for-elementor.This issue affects Premium Addons for Elementor…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 376 CVEsPage 8 of 16