Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Tag: cwe-331 Clear
ID Title
CVE-2026-27490 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue ha...
Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected by a weak 24-bit pseudo-random secret. This issue has been fixed in version 3.2.3.
CVE-2026-19906 Vulnerability in CVE-2026-19906 (CVE-2026-19906)
vulnerability in CVE-2026-19906 (CVE-2026-19906). Risk of unauthorized operations or information disclosure.
CVE-2026-19748 Vulnerability in CVE-2026-19748 (CVE-2026-19748)
vulnerability in CVE-2026-19748 (CVE-2026-19748). Risk of unauthorized operations or information disclosure.
CVE-2026-42155 Vulnerability in openmage/magento-lts (CVE-2026-42155)
vulnerability in openmage/magento-lts (CVE-2026-42155). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/xmlrpc/`. Mitigation: upgrade to `20.18.0` or later.
CVE-2024-20331 Vulnerability in c (CVE-2024-20331)
vulnerability in c (CVE-2024-20331). Risk of unauthorized operations or information disclosure.
CVE-2017-0897 Vulnerability in expressionengine (CVE-2017-0897)
vulnerability in expressionengine (CVE-2017-0897). Confidential information can be exposed externally.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →