Skip to main content

CWE archive

CWE-276 CVEs

Programmatic archive

1,530 CVEs tagged with CWE-276118 Critical, 735 High, 616 Medium, 61 Low, 0 Unrated.

CVE-2020-12075

Published Apr 23, 2020

The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-11692

Published Apr 22, 2020

In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-11689

Published Apr 22, 2020

In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0547

Published Apr 15, 2020

Incorrect default permissions in the installer for Intel(R) Data Migration Software versions 3.3 and earlier may allow an authenticated user to potentially enable escalation of pr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14326

Published Apr 14, 2020

An issue was discovered in AndyOS Andy versions up to 46.11.113. By default, it starts telnet and ssh (ports 22 and 23) with root privileges in the emulated Android system. This c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1985

Published Apr 8, 2020

Incorrect Default Permissions on C:\Programdata\Secdo\Logs folder in Secdo allows local authenticated users to overwrite system files and gain escalated privileges. This issue aff…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-21061

Published Apr 8, 2020

An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) software. A fake charger can execute critical functions in the locked state. The Samsung ID is SVE-2016-63…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-18669

Published Apr 7, 2020

An issue was discovered on Samsung mobile devices with N(7.x) software. Persona has an unprotected API that allows launch of any activity with system privileges. The Samsung ID is…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18668

Published Apr 7, 2020

An issue was discovered on Samsung mobile devices with M(6.0) software. Attackers can prevent users from making outbound calls and sending outbound text messages. The Samsung ID i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7004

Published Apr 3, 2020

VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in elevation of privileges or malicious eff…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-11444

Published Apr 2, 2020

Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3944

Published Apr 1, 2020

Parrot ANAFI is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5551

Published Mar 30, 2020

Toyota 2017 Model Year DCU (Display Control Unit) allows an unauthenticated attacker within Bluetooth range to cause a denial of service attack and/or execute an arbitrary command…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1,301-1,325 of 1,530 CVEsPage 53 of 62