Vulnerabilities (CVE)

Filtered by CWE-668
Total 583 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-42713 2 Microsoft, Splashtop 2 Windows, Splashtop 2023-08-08 7.2 HIGH 7.8 HIGH
Splashtop Remote Client (Personal Edition) through 3.4.6.1 creates a Temporary File in a Directory with Insecure Permissions.
CVE-2021-39971 1 Huawei 1 Harmonyos 2023-08-08 5.0 MEDIUM 7.5 HIGH
Password vault has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability could compromise confidentiality.
CVE-2023-38955 1 Zkteco 1 Bioaccess Ivs 2023-08-07 N/A 7.5 HIGH
ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to obtain sensitive information about all managed devices, including their IP addresses and device names.
CVE-2023-33368 1 Assaabloy 1 Control Id Idsecure 2023-08-04 N/A 6.5 MEDIUM
Some API routes exists in Control ID IDSecure 4.7.26.0 and prior, exfiltrating sensitive information and passwords to users accessing these API routes.
CVE-2023-3670 1 Codesys 2 Development System, Scripting 2023-08-03 N/A 7.3 HIGH
In CODESYS Development System 3.5.9.0 to 3.5.17.0 and CODESYS Scripting 4.0.0.0 to 4.1.0.0 unsafe directory permissions would allow an attacker with local access to the workstation to place potentially harmful and disguised scripts that could be executed by legitimate users.
CVE-2023-39155 1 Jenkins 1 Chef Identity 2023-08-01 N/A 5.3 MEDIUM
Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.
CVE-2022-46901 1 Vocera 2 Report Server, Voice Server 2023-08-01 N/A 7.5 HIGH
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database functions. This includes system tasks, and backing up, loading, and clearing of the database.
CVE-2023-37645 1 Eyoucms 1 Eyoucms 2023-07-27 N/A 5.3 MEDIUM
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.
CVE-2023-32759 1 Archerirm 1 Archer 2023-07-27 N/A 6.5 MEDIUM
An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain sensitive information via a crafted URL.
CVE-2023-37599 1 Issabel 1 Pbx 2023-07-27 N/A 7.5 HIGH
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
CVE-2023-32760 1 Archerirm 1 Archer 2023-07-27 N/A 6.5 MEDIUM
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via API calls related to data feeds and data publication.
CVE-2023-23501 1 Apple 1 Macos 2023-07-27 N/A 5.5 MEDIUM
The issue was addressed with improved memory handling This issue is fixed in macOS Ventura 13.2. An app may be able to disclose kernel memory.
CVE-2023-32394 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2023-07-27 N/A 2.4 LOW
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information from the lock screen.
CVE-2023-31818 1 Marukyu 1 Marukyu Line 2023-07-18 N/A 7.5 HIGH
An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
CVE-2023-3270 1 Sick 2 Icr890-4, Icr890-4 Firmware 2023-07-18 N/A 7.5 HIGH
Exposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the system.
CVE-2023-35696 1 Sick 2 Icr890-4, Icr890-4 Firmware 2023-07-17 N/A 7.5 HIGH
Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via HTTP requests.
CVE-2023-3456 1 Huawei 2 Emui, Harmonyos 2023-07-12 N/A 5.3 MEDIUM
Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-3455 1 Huawei 2 Emui, Harmonyos 2023-07-12 N/A 9.1 CRITICAL
Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.
CVE-2023-32613 1 Wavlink 2 Wl-wn531ax2, Wl-wn531ax2 Firmware 2023-07-06 N/A 8.1 HIGH
Exposure of resource to wrong sphere issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow a network-adjacent attacker to use functions originally available after login without logging in.
CVE-2022-21947 1 Suse 1 Rancher Desktop 2023-07-06 5.8 MEDIUM 8.8 HIGH
A Exposure of Resource to Wrong Sphere vulnerability in Rancher Desktop of SUSE allows attackers in the local network to connect to the Dashboard API (steve) to carry out arbitrary actions. This issue affects: SUSE Rancher Desktop versions prior to V.