Total
434 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-33283 | 1 Marvalglobal | 1 Msm | 2025-01-07 | N/A | 5.5 MEDIUM |
|
Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains access to encrypted secrets can decrypt them by using this key.
|
|||||
| CVE-2023-32414 | 1 Apple | 1 Macos | 2024-12-05 | N/A | 8.6 HIGH |
|
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.4. An app may be able to break out of its sandbox.
|
|||||
| CVE-2023-37301 | 1 Mediawiki | 1 Mediawiki | 2024-11-27 | N/A | 5.3 MEDIUM |
|
An issue was discovered in SubmitEntityAction in Wikibase in MediaWiki through 1.39.3. Because it doesn't use EditEntity for undo and restore, the intended interaction with AbuseFilter does not occur.
|
|||||
| CVE-2020-3549 | 1 Cisco | 2 Firepower Threat Defense, Secure Firewall Management Center | 2024-11-26 | 6.8 MEDIUM | 8.1 HIGH |
|
A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash. The vulnerability is due to insufficient sftunnel negotiation protection during initial device registration. An attacker in a man-in-the-middle position could exploit this vulnerability by intercepting a specific flow of the sftunnel communication between an FMC d ...
Show More |
|||||
| CVE-2024-45273 | 2 Helmholz, Mbconnectline | 27 Myrex24 V2 Virtual Server, Rex 100, Rex 100 Firmware and 24 more | 2024-11-21 | N/A | 8.4 HIGH |
|
An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.
|
|||||
| CVE-2024-34113 | 1 Adobe | 1 Coldfusion | 2024-11-21 | N/A | 5.5 MEDIUM |
|
ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability arises due to the use of insufficiently strong cryptographic algorithms or flawed implementation that compromises the confidentiality of password data. An attacker could exploit this weakness to decrypt or guess passwords, potentially gaining unauthorized access to protected resources. Exploitation of this issue does no ...
Show More |
|||||
| CVE-2024-30119 | 2024-11-21 | N/A | 3.7 LOW | ||
|
HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during redirection.
|
|||||
| CVE-2024-25102 | 2024-11-21 | N/A | 7.8 HIGH | ||
|
This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. An attacker with local administrative privileges could exploit this to obtain the password of AppSamvid on the targeted system.
Successful exploitation of this vulnerability could allow the attacker to take complete control of the application on the targeted system.
|
|||||
| CVE-2024-23656 | 1 Linuxfoundation | 1 Dex | 2024-11-21 | N/A | 7.5 HIGH |
|
Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS 1.1. `cmd/dex/serve.go` line 425 seemingly sets TLS 1.2 as minimum version, but the whole `tlsConfig` is ignored after `TLS cert reloader` was introduced in v2.37.0. Configured cipher suites are not respected either. This issue is fixed in Dex 2.38.0.
|
|||||
| CVE-2024-23580 | 2024-11-21 | N/A | 6.5 MEDIUM | ||
|
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an attacker with access to the database to recover some or all encrypted values.
|
|||||
| CVE-2024-23579 | 2024-11-21 | N/A | 6.5 MEDIUM | ||
|
HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker with access to the database to recover some or all encrypted values.
|
|||||
| CVE-2024-22894 | 2 Alpha-innotec, Novelan | 4 Heat Pumps, Heat Pumps Firmware, Heat Pumps and 1 more | 2024-11-21 | N/A | 6.8 MEDIUM |
|
An issue fixed in AIT-Deutschland Alpha Innotec Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later and Novelan Heatpumps V2.88.3 or later, V3.89.0 or later, V4.81.3 or later, allows remote attackers to execute arbitrary code via the password component in the shadow file.
|
|||||
| CVE-2024-20692 | 1 Microsoft | 14 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 11 more | 2024-11-21 | N/A | 5.7 MEDIUM |
|
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
|
|||||
| CVE-2024-1224 | 2024-11-21 | N/A | 7.1 HIGH | ||
|
This vulnerability exists in USB Pratirodh due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. A local attacker with administrative privileges could exploit this vulnerability to obtain the password of USB Pratirodh on the targeted system.
Successful exploitation of this vulnerability could allow the attacker to take control of the application and modify the access control of registered users or devices on the targeted system.
|
|||||
| CVE-2023-7237 | 1 Lantronix | 2 Xport Edge, Xport Edge Firmware | 2024-11-21 | N/A | 5.7 MEDIUM |
|
Lantronix XPort sends weakly encoded credentials within web request headers.
|
|||||
| CVE-2023-4129 | 1 Dell | 1 Data Protection Central | 2024-11-21 | N/A | 5.9 MEDIUM |
|
Dell Data Protection Central, version 19.9, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, allowing an attacker to recover plaintext from a block of ciphertext.
|
|||||
| CVE-2023-48051 | 1 Carglglz | 1 Upydev | 2024-11-21 | N/A | 7.5 HIGH |
|
An issue in /upydev/keygen.py in upydev v0.4.3 allows attackers to decrypt sensitive information via weak encryption padding.
|
|||||
| CVE-2023-48034 | 1 Acer | 2 Sk-9662, Sk-9662 Firmware | 2024-11-21 | N/A | 6.1 MEDIUM |
|
An issue discovered in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject arbitrary keystrokes via use of weak encryption.
|
|||||
| CVE-2023-47373 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
|
The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims.
|
|||||
| CVE-2023-47372 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
|
The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
|
|||||
| CVE-2023-47370 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
|
The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims.
|
|||||
| CVE-2023-47369 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
|
The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications.
|
|||||
| CVE-2023-47368 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
|
The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims.
|
|||||
| CVE-2023-47367 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
|
The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims.
|
|||||
| CVE-2023-47366 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
|
The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims.
|
|||||
| CVE-2023-47365 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
|
The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
|
|||||
| CVE-2023-47364 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
|
The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications to victims
|
|||||
| CVE-2023-47363 | 1 Linecorp | 1 Line | 2024-11-21 | N/A | 6.5 MEDIUM |
|
The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims.
|
|||||
| CVE-2023-46894 | 1 Espressif | 1 Esptool | 2024-11-21 | N/A | 7.5 HIGH |
|
An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.
|
|||||
| CVE-2023-44690 | 1 Dbcli | 1 Mycli | 2024-11-21 | N/A | 7.5 HIGH |
|
Inadequate encryption strength in mycli 1.27.0 allows attackers to view sensitive information via /mycli/config.py
|
|||||
| CVE-2023-43776 | 1 Eaton | 44 Easy-box-e4-ac1, Easy-box-e4-ac1 Firmware, Easy-box-e4-dc1 and 41 more | 2024-11-21 | N/A | 6.8 MEDIUM |
|
Eaton easyE4 PLC offers a device password protection functionality to facilitate a secure connection and prevent unauthorized access. It was observed that the device password was stored with a weak encoding algorithm in the easyE4 program file when exported to SD card (*.PRG file ending).
|
|||||
| CVE-2023-43757 | 1 Elecom | 68 Lan-w300n\/p, Lan-w300n\/p Firmware, Lan-w300n\/rs and 65 more | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN communication and intercept the communication. As for the affected products/versions, see the information provided by the vendor under [References] section.
|
|||||
| CVE-2023-41305 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | N/A | 7.5 HIGH |
|
Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality.
|
|||||
| CVE-2023-3243 | 1 Honeywell | 2 Alerton Bcm-web, Alerton Bcm-web Firmware | 2024-11-21 | N/A | 8.3 HIGH |
|
** UNSUPPORTED WHEN ASSIGNED ** [An attacker can capture an authenticating hash
and utilize it to create new sessions. The hash is also a poorly salted MD5
hash, which could result in a successful brute force password attack. Impacted product is BCM-WEB version 3.3.X. Recommended fix: Upgrade to a supported product such
as Alerton
ACM.] Out of an abundance of caution, this CVE ID is being assigned to
better serve our customers and ensure all who are still running this product understand
that ...
Show More |
|||||
| CVE-2023-37397 | 1 Ibm | 1 Aspera Faspex | 2024-11-21 | N/A | 3.6 LOW |
|
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive information due to improper encryption of certain data. IBM X-Force ID: 259672.
|
|||||
| CVE-2023-36748 | 1 Siemens | 22 Ruggedcom Rox Mx5000, Ruggedcom Rox Mx5000 Firmware, Ruggedcom Rox Mx5000re and 19 more | 2024-11-21 | N/A | 5.9 MEDIUM |
|
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < ...
Show More |
|||||
| CVE-2023-36539 | 1 Zoom | 14 Meetings, Poly Ccx 600, Poly Ccx 600 Firmware and 11 more | 2024-11-21 | N/A | 5.3 MEDIUM |
|
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.
|
|||||
| CVE-2023-35332 | 1 Microsoft | 12 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 9 more | 2024-11-21 | N/A | 6.8 MEDIUM |
|
Windows Remote Desktop Protocol Security Feature Bypass
|
|||||
| CVE-2023-34971 | 1 Qnap | 2 Qts, Quts Hero | 2024-11-21 | N/A | 7.1 HIGH |
|
An inadequate encryption strength vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerability possibly allows local network clients to decrypt the data using brute force attacks via unspecified vectors.
We have already fixed the vulnerability in the following versions:
QTS 5.0.1.2425 build 20230609 and later
QTS 5.1.0.2444 build 20230629 and later
QTS 4.5.4.2467 build 20230718 and later
QuTS hero h5.1.0.2424 build 20230609 and later
QuTS hero h4.5.4.2476 bu ...
Show More |
|||||
| CVE-2023-34337 | 1 Ami | 1 Megarac Sp-x | 2024-11-21 | N/A | 7.6 HIGH |
|
AMI SPx contains a vulnerability in the BMC where a user may cause an inadequate encryption strength by hash-based message authentication code (HMAC). A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.
|
|||||