CWE-254
308 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-254page 7 of 7
- CVE-2018-6336HIGHCVSS 7.8EG 7.82018-12-31
An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the…
- CVE-2019-10059MEDIUMCVSS 5.3EG 5.32019-08-28
The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.
- CVE-2019-10741MEDIUMCVSS 4.3EG 4.32019-04-07
K-9 Mail v5.600 can include the original quoted HTML code of a specially crafted, benign looking, email within (digitally signed) reply messages. The quoted part can contain conditional statements that show completely different text if ope…
- CVE-2019-11636HIGHCVSS 7.5EG 7.52019-05-01
Zcash 2.x allows an inexpensive approach to "fill all transactions of all blocks" and "prevent any real transaction from occurring" via a "Sapling Wood-Chipper" attack.
- CVE-2019-15149CRITICALCVSS 9.8EG 9.82019-08-18
core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. NOTE: the vendor disputes this issue beca…
- CVE-2019-5495HIGHCVSS 7.5EG 7.52019-05-10
OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors.
- CVE-2021-40006MEDIUMCVSS 4.6EG 4.62022-01-10
Vulnerability of design defects in the security algorithm component. Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2021-43177MEDIUMCVSS 5.3EG 5.32022-04-11
As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR…
Map vulnerabilities like CWE-254 to your infrastructure
EchelonGraph correlates every CVE — across CWE-254 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →