Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,880 CVEs tagged with CWE-3061,083 Critical, 1,120 High, 626 Medium, 51 Low, 0 Unrated.

CVE-2019-13406

Published Aug 29, 2019

A broken access control vulnerability found in Advan VD-1 firmware versions up to 230. An attacker can send a POST request to cgibin/ApkUpload.cgi to install arbitrary APK without…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13405

Published Aug 29, 2019

A broken access control vulnerability found in Advan VD-1 firmware version 230 leads to insecure ADB service. An attacker can send a POST request to cgibin/AdbSetting.cgi to enabl…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11063

Published Aug 29, 2019

A broken access control vulnerability in SmartHome app (Android versions up to 3.0.42_190515, ios versions up to 2.0.22) allows an attacker in the same local area network to list…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11061

Published Aug 29, 2019

A broken access control vulnerability in HG100 firmware versions up to 4.00.06 allows an attacker in the same local area network to control IoT devices that connect with itself vi…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-15506

Published Aug 26, 2019

An issue was discovered in Kaseya Virtual System Administrator (VSA) through 9.4.0.37. It has a critical information disclosure vulnerability. An unauthenticated attacker can send…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14511

Published Aug 22, 2019

Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet (unless filtered by a firewall or reconfigured to liste…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15129

Published Aug 18, 2019

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by spec…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15106

Published Aug 16, 2019

An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirement and execute commands on the server. The "username+'@opm…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-13101

Published Aug 8, 2019

An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without authentication, which can lead to disclosure of information…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-5451

Published Jul 30, 2019

Bypass lock protection in the Nextcloud Android app prior to version 3.6.1 allows accessing the files when repeatedly opening and closing the app in a very short time.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3948

Published Jul 29, 2019

The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0.R, Dahua DH-IPC HX883X and DH-IPC-HX863X V2.622.0000000.7.…

CVSS 7.5 · High

CVE-2019-13983

Published Jul 19, 2019

Directus 7 API before 2.2.2 has insufficient anti-automation, as demonstrated by lack of a CAPTCHA in core/Directus/Services/AuthService.php and endpoints/Auth.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12468

Published Jul 10, 2019

An Incorrect Access Control vulnerability was found in Wikimedia MediaWiki 1.27.0 through 1.32.1. Directly POSTing to Special:ChangeEmail would allow for bypassing re-authenticati…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 2,676-2,700 of 2,880 CVEsPage 108 of 116