Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,789 CVEs tagged with CWE-3061,056 Critical, 1,069 High, 614 Medium, 50 Low, 0 Unrated.

CVE-2021-41975

Published Oct 8, 2021

TadTools special page is vulnerable to authorization bypass, thus remote attackers can use the specific parameter to delete arbitrary files in the system without logging in.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41974

Published Oct 8, 2021

Tad Book3 editing book page does not perform identity verification. Remote attackers can use the vulnerability to view and modify arbitrary content of books without permission.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-41568

Published Oct 8, 2021

Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original function of viewing bulletin boards and uploading files in t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39879

Published Oct 4, 2021

Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

CVSS 2.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-3825

Published Oct 1, 2021

On 2.1.15 version and below of Lider module in LiderAhenk software is leaking it's configurations via an unsecured API. An attacker with an access to the configurations API could…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10941

Published Sep 14, 2021

A vulnerability has been identified in SINEMA Server (All versions < V14 SP3). Missing authentication for functionality that requires administrative user identity could allow an a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38540

Published Sep 9, 2021

The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticated users to hit that endpoint to add/modify Airflow variable…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-32800

Published Sep 7, 2021

Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two Factor Authentication in Nextcloud. Thus knowledge of a pass…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37415

Published Sep 1, 2021

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
52.6
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-27668

Published Aug 31, 2021

HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authentication. Fixed in 1.6.3.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-31868

Published Aug 19, 2021

Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feature, regardless of the assignm…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35936

Published Aug 16, 2021

If remote logging is not used, the worker (in the case of CeleryExecutor) or the scheduler (in the case of LocalExecutor) runs a Flask logging server and is listening on a specifi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37697

Published Aug 11, 2021

tmerc-cogs are a collection of open source plugins for the Red Discord bot. A vulnerability has been found in the code that allows any user to access sensitive information by craf…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37696

Published Aug 11, 2021

tmerc-cogs are a collection of open source plugins for the Red Discord bot. A vulnerability has been found in the code that allows any user to access sensitive information by craf…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25566

Published Aug 11, 2021

In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in POC. Notice that we do not require a JSESSIONID in this reque…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 2,126-2,150 of 2,789 CVEsPage 86 of 112