Skip to main content

CWE archive

CWE-269 CVEs

Programmatic archive

2,988 CVEs tagged with CWE-269381 Critical, 1,798 High, 731 Medium, 77 Low, 1 Unrated.

CVE-2019-4477

Published Sep 17, 2019

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a user with access to audit logs to obtain sensitive information, caused by improper handling of command line o…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10972

Published Sep 16, 2019

The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-10971

Published Sep 16, 2019

The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowlewdge of an e-mail address is required.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10968

Published Sep 16, 2019

The peepso-core plugin before 1.6.1 for WordPress has PeepSoProfilePreferencesAjax->save() privilege escalation.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16202

Published Sep 10, 2019

MISP before 2.4.115 allows privilege escalation in certain situations. After updating to 2.4.115, escalation attempts are blocked by the __checkLoggedActions function with a "This…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6997

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting in 10.7) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6996

Published Sep 9, 2019

An issue was discovered in GitLab Enterprise Edition 10.x (starting in 10.6) and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Contro…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6794

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 5 of 6).…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6789

Published Sep 9, 2019

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Information Disclosure (issue 4 of 6).…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-21013

Published Sep 9, 2019

The Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via vectors involving xmlPath to wp-admin/admin-aja…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9443

Published Sep 6, 2019

In the Android kernel in the vl53L0 driver there is a possible out of bounds write due to a permissions bypass. This could lead to local escalation of privilege due to a set_fs()…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1939

Published Sep 5, 2019

A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. This vulnerability…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4536

Published Aug 29, 2019

IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles with elevated privileges caus…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15720

Published Aug 28, 2019

CloudBerry Backup v6.1.2.34 allows local privilege escalation via a Pre or Post backup action. With only user-level access, a user can modify the backup plan and add a Pre backup…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12889

Published Aug 20, 2019

An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2. A user with local access to only the Windows logon screen can escalate their privileges to…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort
Showing 2,626-2,650 of 2,988 CVEsPage 106 of 120