Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,789 CVEs tagged with CWE-3061,056 Critical, 1,069 High, 614 Medium, 50 Low, 0 Unrated.

CVE-2010-5326

Published May 13, 2016

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary co…

CVSS 10.0 · Critical
evidence mentions
8
Buzz score
56.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2016-2004

Published Apr 21, 2016

HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2014-9197

Published Jan 27, 2015

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote atta…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2014-4872

Published Oct 10, 2014

BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive cre…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2011-3055

Published Mar 22, 2012

The browser native UI in Google Chrome before 17.0.963.83 does not require user confirmation before an unpacked extension installation, which allows user-assisted remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6827

Published Jun 8, 2009

The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1780

Published May 22, 2009

admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileg…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0213

Published Aug 6, 2004

Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" s…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 2,776-2,789 of 2,789 CVEsPage 112 of 112