Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,880 CVEs tagged with CWE-3061,083 Critical, 1,120 High, 626 Medium, 51 Low, 0 Unrated.

CVE-2019-10042

Published Mar 25, 2019

The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/Load…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10041

Published Mar 25, 2019

The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/form…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10040

Published Mar 25, 2019

The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use a hidden API URL /gofor…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10039

Published Mar 25, 2019

The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request. An attacker can get this token from dir_login.asp and use an API URL /goform/setS…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-19636

Published Mar 5, 2019

Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides one at an arbitrary location…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0261

Published Feb 15, 2019

Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced) does not perform authentication checks properly for XS advanced platform and busi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-7390

Published Feb 5, 2019

An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to hijack the DNS service con…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7389

Published Feb 5, 2019

An issue was discovered in /bin/goahead on D-Link DIR-823G devices with the firmware 1.02B03. There is incorrect access control allowing remote attackers to reset the router witho…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6447

Published Jan 16, 2019

The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on…

CVSS 8.1 · High
evidence mentions
1
Buzz score
15.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2018-15466

Published Jan 11, 2019

A vulnerability in the Graphite web interface of the Policy and Charging Rules Function (PCRF) of Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to acces…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0246

Published Jan 8, 2019

SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 2,751-2,775 of 2,880 CVEsPage 111 of 116