Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,699 CVEs tagged with CWE-3061,020 Critical, 1,018 High, 612 Medium, 49 Low, 0 Unrated.

CVE-2020-3531

Published Nov 18, 2020

A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end database of an affected system. Th…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-3392

Published Nov 18, 2020

A vulnerability in the API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulne…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-26824

Published Nov 10, 2020

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Legacy Ports…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-26823

Published Nov 10, 2020

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Upgrade Diagnostics A…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-26822

Published Nov 10, 2020

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the Outside Discovery Con…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-26821

Published Nov 10, 2020

SAP Solution Manager (JAVA stack), version - 7.20, allows an unauthenticated attacker to compromise the system because of missing authorization checks in the SVG Converter Service…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-13927

Published Nov 10, 2020

The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but this poses security risks to users who miss this fact. From A…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
46.0
Vendor/product tagsBeta · best-effort

CVE-2020-7128

Published Nov 4, 2020

A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27986

Published Oct 28, 2020

SonarQube 8.4.2.36762 allows remote attackers to discover cleartext SMTP, SVN, and GitLab credentials via the api/settings/values URI. NOTE: reportedly, the vendor's position for…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25966

Published Oct 28, 2020

Sectona Spectra before 3.4.0 has a vulnerable SOAP API endpoint that leaks sensitive information about the configured assets without proper authentication. This could be used by u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11764

Published Oct 21, 2020

Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7370

Published Oct 20, 2020

User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of Danyil Vasilenko's Bolt Browser allows an attacker to obfuscate the true source o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7369

Published Oct 20, 2020

User Interface (UI) Misrepresentation of Critical Information vulnerability in the address bar of the Yandex Browser allows an attacker to obfuscate the true source of data as pre…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25824

Published Oct 14, 2020

Telegram Desktop through 2.4.3 does not require passcode entry upon pushing the Export key within the Export Telegram Data wizard. The threat model is a victim who has voluntarily…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-15243

Published Oct 8, 2020

Affected versions of Smartstore have a missing WebApi Authentication attribute. This vulnerability affects Smartstore shops in version 4.0.0 & 4.0.1 which have installed and activ…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-26567

Published Oct 8, 2020

An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed without authentication. Any access reboots the device, rend…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-3598

Published Oct 8, 2020

A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to access confidential information o…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26876

Published Oct 7, 2020

The wp-courses plugin through 2.0.27 for WordPress allows remote attackers to bypass the intended payment step (for course videos and materials) by using the /wp-json REST API, as…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26599

Published Oct 6, 2020

An issue was discovered on Samsung mobile devices with Q(10.0) software. The DynamicLockscreen Terms and Conditions can be accepted without authentication. The Samsung ID is SVE-2…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,201-2,225 of 2,699 CVEsPage 89 of 108