VulnSea

CWE-200

CVEs classified under CWE-200, newest first.

824 CVEsRSS

CVE-2022-1353High· 7.1
4y ago

A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel

A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of internal kernel informa…

▾ Twilightlinux · linux_kernelEPSS 0.40%via NVD
CVE-2022-0577Medium· 6.5
4y ago

Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy

Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy

▾ Sunlitscrapy · scrapyEPSS 1.3%via OSV
CVE-2021-45421High· 7.5
4y ago

Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing

Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to access all the files in the remote directories. Note: the product has not been supported…

▾ Twilightemerson · dixell_xweb-500_firmwareEPSS 1.3%via NVD
CVE-2021-45420Critical· 9.8PoC
4y ago

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system with…

▾ Abyssalemerson · dixell_xweb-500_firmwareEPSS 18%via NVD
CVE-2021-40690High· 7.5
5y ago

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element

All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allo…

▾ Twilightapache · santuario_xml_security_for_javaEPSS 7.4%via NVD
CVE-2021-38554Medium· 5.3
5y ago

vault: UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser (CVE-2021-38554)

A flaw was found in the vault package. The Vault UI web application may fail to completely clear a client-side data cache on user logout. As a result, an authenticated user sharing a browser to access Vault may have been able to view the p…

▾ SunlitRed Hat · Red Hat Openshift Container Storage 4EPSS 0.91%via CSAF
CVE-2021-25122High· 7.5
5y ago

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…

▾ Twilightapache · tomcatEPSS 18%via NVD
CVE-2021-24122Medium· 5.9
5y ago

When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some con…

When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some con…

▾ Sunlitapache · tomcatEPSS 23%via NVD
CVE-2020-26869High· 7.5
5y ago

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitimate users

ARC Informatique PcVue prior to version 12.0.17 is vulnerable to information exposure, allowing unauthorized users to access session data of legitimate users. This issue also affects third-party systems based on the Web Services Toolkit.

▾ Twilightarcinformatique · pcvueEPSS 1.7%via NVD
CVE-2020-15671Low· 3.1
5y ago

When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary

When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerabilit…

▾ Sunlitmozilla · firefox_mobileEPSS 0.49%via NVD
CVE-2020-6830High· 7.5
6y ago

For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions

For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was als…

▾ Twilightmozilla · firefox_mobileEPSS 0.90%via NVD
CVE-2020-3259High· 7.5CISA KEV
6y ago

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affecte…

A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affecte…

▾ Abyssalcisco · secure_firewall_threat_defenseEPSS 72%via NVD
CVE-2011-4088High· 7.5
6y ago

ABRT might allow attackers to obtain sensitive information from crash reports.

ABRT might allow attackers to obtain sensitive information from crash reports.

▾ Twilightredhat · automatic_bug_reporting_toolEPSS 1.6%via NVD
CVE-2016-6650High· 7.5
9y ago

EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system.

EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system.

▾ Twilightdell · recoverpoint_for_virtual_machinesEPSS 1.6%via NVD
CWE-200 vulnerabilities (CVEs) — page 28 · VulnSea