Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-668

MITRE ↗

CWE-668

64
CRITICAL
235
HIGH
360
MEDIUM
55
LOW
731 CVEs · Page 6/15
5.5
CVE-2023-21687

HTTP.sys Information Disclosure Vulnerability

5.5
CVE-2023-21714

Microsoft Office Information Disclosure Vulnerability

5.5
CVE-2023-23501

The issue was addressed with improved memory handling This issue is fixed in macOS Ventura 13.2. An app may be able to d

5.5
CVE-2023-23394

Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability

5.5
CVE-2023-23409

Client Server Run-Time Subsystem (CSRSS) Information Disclosure Vulnerability

5.5
CVE-2023-25954

KYOCERA Mobile Print' v3.2.0.230119 and earlier, 'UTAX/TA MobilePrint' v3.2.0.230119 and earlier, and 'Olivetti Mobile P

5.5
CVE-2023-22307

Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords

5.5
CVE-2023-29820

An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to a

5.5
CVE-2023-41745

Sensitive information disclosure due to excessive collection of system information. The following products are affected:

5.5
CVE-2023-38558

A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Ad

5.5
CVE-2023-43782

Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/.cadence-aloop-daemon.x Temporary File. The file is used even if

5.5
CVE-2023-32275

An information disclosure vulnerability exists in the CtEnumCa() functionality of SoftEther VPN 4.41-9782-beta and 5.01.

5.5
CVE-2023-4910

A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and then presses the back butt

5.5
CVE-2023-42546

Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account pr

5.5
CVE-2023-42547

Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prio

5.5
CVE-2023-42549

Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior

5.5
CVE-2023-42551

Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version

5.5
CVE-2023-42715

In telephony service, there is a possible missing permission check. This could lead to local information disclosure with

5.5
CVE-2023-42718

In dialer, there is a possible way to write permission usage records of an app due to a missing permission check. This c

5.3
CVE-2022-45438

When explicitly enabling the feature flag DASHBOARD_CACHE (disabled by default), the system allowed for an unauthenticat

5.3
CVE-2023-25192

AMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-updat

5.3
CVE-2023-23448

Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 110021

5.3
CVE-2023-33293

An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localh

5.3
CVE-2023-33518

emoncms v11 and later was discovered to contain an information disclosure vulnerability which allows attackers to obtain

5.3
CVE-2023-29355

DHCP Server Service Information Disclosure Vulnerability

5.3
CVE-2023-3456

Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability

5.3
CVE-2023-37645

eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/re

5.3
CVE-2023-39155

Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for a

5.3
CVE-2023-39974

Exposure of Sensitive Information vulnerability in AcyMailing Enterprise component for Joomla. It allows unauthorized ac

5.3
CVE-2023-4230

A vulnerability has been identified in ioLogik 4000 Series (ioLogik E4200) firmware versions v1.6 and prior, which has t

5.3
CVE-2023-38152

DHCP Server Service Information Disclosure Vulnerability

5.3
CVE-2023-40788

SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway res

5.3
CVE-2023-30802

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A

5.3
CVE-2023-44102

Broadcast permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability can cau

5.0
CVE-2022-4903

A vulnerability was found in CodenameOne 7.0.70. It has been classified as problematic. Affected is an unknown function.

5.0
CVE-2023-2025

OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorize

4.9
CVE-2023-22777

An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful e

4.8
CVE-2023-34250

Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 o

4.7
CVE-2023-21536

Event Tracing for Windows Information Disclosure Vulnerability

4.7
CVE-2023-32019

Windows Kernel Information Disclosure Vulnerability

4.4
CVE-2022-34364

Dell BSAFE SSL-J, versions before 6.5 and version 7.0 contain a debug message revealing unnecessary information vulne

4.3
CVE-2022-46257

An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to

4.3
CVE-2023-1402

The course participation report required additional checks to prevent roles being displayed which the user did not have

4.3
CVE-2023-28336

Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not

4.3
CVE-2023-1775

When running in a High Availability configuration, Mattermost fails to sanitize some of the user_updated and post_delete

4.3
CVE-2021-30153

An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35

4.3
CVE-2023-25750

Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private brows

4.3
CVE-2023-29538

Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-ext

4.3
CVE-2023-30960

A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resour

4.3
CVE-2022-20917

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber coul

Frequently Asked Questions

What is CWE-668?

CWE-668 (CWE-668) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-668?

There are 817 CVE records associated with CWE-668 in our database. Of these, 64 are critical severity, 235 are high severity, and 360 are medium severity.

How can I protect against CWE-668 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-668 using AI-powered security agents.

Detect CWE-668 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-668 vulnerabilities across your infrastructure.

Get Started