Skip to main content

CWE archive

CWE-254 CVEs

Programmatic archive

414 CVEs tagged with CWE-25437 Critical, 126 High, 220 Medium, 31 Low, 0 Unrated.

CVE-2021-43177

Published Apr 11, 2022

As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immedi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40006

Published Jan 10, 2022

Vulnerability of design defects in the security algorithm component. Successful exploitation of this vulnerability may affect confidentiality.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10933

Published Aug 26, 2019

An issue was discovered in the portaudio crate through 0.7.0 for Rust. There is a man-in-the-middle issue because the source code is downloaded over cleartext HTTP.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10932

Published Aug 26, 2019

An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-middle vulnerability because hostname verification was omitted.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-9331

Published Aug 20, 2019

The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15149

Published Aug 18, 2019

core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extens…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-18480

Published Aug 5, 2019

cPanel before 62.0.4 does not enforce account ownership for has_mycnf_for_cpuser WHM API calls (SEC-210).

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18477

Published Aug 5, 2019

In cPanel before 62.0.4, Exim transports could execute in the context of the nobody account (SEC-206).

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18476

Published Aug 5, 2019

Leech Protect in cPanel before 62.0.4 does not protect certain directories (SEC-205).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10772

Published Aug 5, 2019

cPanel before 60.0.25 does not enforce feature-list restrictions when calling the multilang adminbin (SEC-168).

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-18467

Published Aug 5, 2019

cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18462

Published Aug 5, 2019

cPanel before 62.0.17 allows a CPHulk one-day ban bypass when IP based protection is enabled (SEC-224).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18445

Published Aug 2, 2019

cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18429

Published Aug 2, 2019

In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-8227

Published Jul 3, 2019

Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are detected using the Web and HTTP API inter…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-13718

Published Jun 10, 2019

The HTTP API supported by Starry Station (aka Starry Router) allows brute forcing the PIN setup by the user on the device, and this allows an attacker to change the Wi-Fi settings…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5495

Published May 10, 2019

OnCommand Unified Manager for VMware vSphere, Linux and Windows prior to 9.5 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11636

Published May 1, 2019

Zcash 2.x allows an inexpensive approach to "fill all transactions of all blocks" and "prevent any real transaction from occurring" via a "Sapling Wood-Chipper" attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1428

Published Apr 22, 2019

A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affects Ubuntu MAAS versions prior to 1.9.2.

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-10746

Published Apr 18, 2019

libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a dif…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 414 CVEsPage 1 of 17