Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,789 CVEs tagged with CWE-3061,056 Critical, 1,069 High, 614 Medium, 50 Low, 0 Unrated.

CVE-2020-25563

Published Aug 11, 2021

In SapphireIMS 5.0, it is possible to create local administrator on any client without requiring any credentials by directly accessing RemoteMgmtTaskSave (Automation Tasks) featur…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-37843

Published Aug 2, 2021

The resolution SAML SSO apps for Atlassian products allow a remote attacker to login to a user account when only the username is known (i.e., no other authentication is provided).…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7389

Published Jul 22, 2021

Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-22784

Published Jul 21, 2021

A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain rem…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-21936

Published Jul 21, 2021

An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSettings, GetWebsiteFilterSettings…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36124

Published Jul 13, 2021

An issue was discovered in Echo ShareCare 8.15.5. It does not perform authentication or authorization checks when accessing a subset of sensitive resources, leading to the ability…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-28809

Published Jul 8, 2021

An improper access control vulnerability has been reported to affect certain legacy versions of HBS 3. If exploited, this vulnerability allows attackers to compromise the security…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2021-20474

Published Jul 7, 2021

IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not perform any authentication for functionality that requires a provable user identity or consumes a significant amoun…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34621

Published Jul 7, 2021

A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-32709

Published Jun 24, 2021

Shopware is an open source eCommerce platform. Creation of order credits was not validated by ACL in admin orders. Users are recommend to update to the current version 6.4.1.1. Yo…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33346

Published Jun 24, 2021

There is an arbitrary password modification vulnerability in a D-LINK DSL-2888A router product. An attacker can use this vulnerability to modify the password of the admin user wit…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-32700

Published Jun 22, 2021

Ballerina is an open source programming language and platform for cloud application programmers. Ballerina versions 1.2.x and SL releases up to alpha 3 have a potential for a supp…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-32659

Published Jun 16, 2021

Matrix-appservice-bridge is the bridging service for the Matrix communication program's application services. In versions 2.6.0 and earlier, if a bridge has room upgrade handling…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32930

Published Jun 11, 2021

The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute arbitrary code on the iView (ver…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-26928

Published Jun 4, 2021

BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for example, include Tigera product…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,151-2,175 of 2,789 CVEsPage 87 of 112