CVE Database

31+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS

31 results for "CWE-20"

CVE-2026-41244
4.7 MEDIUM

Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the CipherEngine uses a standard …

Apr 24, 2026
CVE-2025-52457
5.7 MEDIUM

Observable Timing Discrepancy (CWE-208) in HBUS devices may allow an attacker with physical access to the device to extract device-specific keys, potentially compromising further site …

Nov 18, 2025
CVE-2025-55058
4.5 MEDIUM

CWE-20 Improper Input Validation

Nov 17, 2025
CVE-2025-59921
6.5 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, version 7.1.4 and below, 7.0 …

Oct 14, 2025
CVE-2025-55052
4.3 MEDIUM

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Sep 9, 2025
CVE-2025-46388
4.3 MEDIUM

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Aug 6, 2025
CVE-2025-46382
5.3 MEDIUM

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Jul 20, 2025
CVE-2025-25250
4.3 MEDIUM

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS version 7.6.0, version 7.4.7 and below, 7.2 all versions, 7.0 all versions, …

Jun 10, 2025
CVE-2025-3898
6.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends HTTPS request containing invalid data type to …

Jun 10, 2025
CVE-2025-3116
6.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an authenticated malicious user sends special malformed HTTPS request containing improper formatted …

Jun 10, 2025
CVE-2025-23182
4.3 MEDIUM

CWE-203: Observable Discrepancy

May 22, 2025
CVE-2025-0816
6.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious IPV6 packets are sent to the device.

Feb 13, 2025
CVE-2025-0815
6.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the product when malicious ICMPV6 packets are sent to the device.

Feb 13, 2025
CVE-2025-0814
5.3 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network services running on the product when malicious IEC61850-MMS packets are sent to …

Feb 13, 2025
CVE-2024-10083
5.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated …

Feb 13, 2025
CVE-2025-1101
5.3 MEDIUM

A CWE-204 "Observable Response Discrepancy" in the login page in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to …

Feb 12, 2025
CVE-2024-36510
5.3 MEDIUM

An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 …

Jan 14, 2025
CVE-2024-47923
5.3 MEDIUM

Mashov – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Dec 30, 2024
CVE-2024-8936
6.5 MEDIUM

CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a …

Nov 13, 2024
CVE-2023-44255
4.1 MEDIUM

An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a …

Nov 12, 2024
CVE-2024-42343
5.3 MEDIUM

Loway - CWE-204: Observable Response Discrepancy

Sep 8, 2024
CVE-2024-42339
4.3 MEDIUM

CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Aug 25, 2024
CVE-2024-42338
4.3 MEDIUM

CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Aug 25, 2024
CVE-2024-42337
4.3 MEDIUM

CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Aug 25, 2024
CVE-2024-41698
4.3 MEDIUM

Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Aug 20, 2024
CVE-2024-31200
4.2 MEDIUM

A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the …

Jul 31, 2024
CVE-2024-41701
5.3 MEDIUM

AccuPOS - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Jul 30, 2024
CVE-2024-41694
5.3 MEDIUM

Cybonet - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Jul 30, 2024
CVE-2024-38431
5.3 MEDIUM

Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy

Jul 30, 2024
CVE-2024-23107
5.5 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, 6.3 all …

Jun 3, 2024
CVE-2023-44253
5.0 MEDIUM

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through …

Feb 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.