Skip to main content

CWE archive

CWE-276 CVEs

Programmatic archive

1,530 CVEs tagged with CWE-276118 Critical, 735 High, 616 Medium, 61 Low, 0 Unrated.

CVE-2020-13240

Published May 20, 2020

The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11716

Published May 20, 2020

Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the vendor states that all affected products are at "End-of-so…

CVSS 9.8 · Critical

CVE-2020-13149

Published May 18, 2020

Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Micro-Star MSI Gaming laptops, allows local authenticated user…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0024

Published May 14, 2020

In onCreate of SettingsBaseActivity.java, there is a possible unauthorized setting modification due to a permissions bypass. This could lead to local escalation of privilege with…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2183

Published May 6, 2020

Jenkins Copy Artifact Plugin 1.43.1 and earlier performs improper permission checks, allowing attackers to copy artifacts from jobs they have no permission to access.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8018

Published May 4, 2020

A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of SUSE Linux Enterprise Server 15 SP1 allows local attackers…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-12101

Published Apr 30, 2020

The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST requ…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12277

Published Apr 29, 2020

GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-12118

Published Apr 23, 2020

The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensi…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort
Showing 1,276-1,300 of 1,530 CVEsPage 52 of 62