Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,933 CVEs tagged with CWE-3061,100 Critical, 1,147 High, 634 Medium, 52 Low, 0 Unrated.

CVE-2022-36521

Published Aug 26, 2022

Insecure permissions in cskefu v7.0.1 allows unauthenticated attackers to arbitrarily add administrator accounts.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2552

Published Aug 22, 2022

The Duplicator WordPress plugin before 1.4.7 does not authenticate or authorize visitors before displaying information about the system such as server software, php version and fu…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-37062

Published Aug 18, 2022

All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory access restriction. An unauth…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35122

Published Aug 17, 2022

An access control issue in Ecowitt GW1100 Series Weather Stations <=GW1100B_v2.1.5 allows unauthenticated attackers to access sensitive information including device and local WiFi…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-2242

Published Aug 10, 2022

The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write robot configurations when acce…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-35865

Published Aug 3, 2022

This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It! 20.21.2.109. Authentication is not required to exploit this vulnera…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-36884

Published Jul 27, 2022

The webhook endpoint in Jenkins Git Plugin 4.11.3 and earlier provide unauthenticated attackers information about the existence of jobs configured to use an attacker-specified Git…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36129

Published Jul 26, 2022

HashiCorp Vault Enterprise 1.7.0 through 1.9.7, 1.10.4, and 1.11.0 clusters using Integrated Storage expose an unauthenticated API endpoint that could be abused to override the vo…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-29957

Published Jul 26, 2022

The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. Th…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29952

Published Jul 26, 2022

Bently Nevada condition monitoring equipment through 2022-04-29 mishandles authentication. It utilizes the TDI command and data protocols (60005/TCP, 60007/TCP) for communications…

CVSS 9.1 · Critical

CVE-2022-35871

Published Jul 25, 2022

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not require…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2138

Published Jul 22, 2022

The affected product is vulnerable due to missing authentication, which may allow an attacker to read or modify sensitive data and execute arbitrary code, resulting in a denial-of…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-20861

Published Jul 21, 2022

Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 2,101-2,125 of 2,933 CVEsPage 85 of 118