Skip to main content

CWE archive

CWE-306 CVEs

Programmatic archive

2,580 CVEs tagged with CWE-306941 Critical, 982 High, 608 Medium, 49 Low, 0 Unrated.

CVE-2020-10965

Published Mar 25, 2020

Teradici PCoIP Management Console 20.01.0 and 19.11.1 is vulnerable to unauthenticated password resets via login/resetadminpassword of the default admin account. This vulnerabilit…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20624

Published Mar 24, 2020

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. S-Voice leaks keyboard learned words via the lock screen. The Samsung ID is SVE-2018-12981 (Febr…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20598

Published Mar 24, 2020

An issue was discovered on Samsung mobile devices with O(8.x) software. Bixby leaks the keyboard's learned words, and the clipboard contents, via the lock screen. The Samsung IDs…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-20595

Published Mar 24, 2020

An issue was discovered on Samsung mobile devices with P(9.0) software. Quick Panel allows enabling or disabling the Bluetooth stack without authentication. The Samsung ID is SVE-…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-20579

Published Mar 24, 2020

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Gallery allows attackers to enable Location information sharing from the lock screen. T…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-20559

Published Mar 24, 2020

An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery allows viewing of photos on the lock screen. The Samsung ID is SVE-2019-15055 (October 2019).

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-20550

Published Mar 24, 2020

An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. T…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10833

Published Mar 24, 2020

An issue was discovered on Samsung mobile devices with Q(10.0) software. The DeX Lockscreen allows attackers to access the quick panel and notifications. The Samsung ID is SVE-201…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20532

Published Mar 24, 2020

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can access the Developer options without authentication. The Samsung ID is S…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-8497

Published Mar 23, 2020

In Artica Pandora FMS through 7.42, an unauthenticated attacker can read the chat history. The file is in JSON format and it contains user names, user IDs, private messages, and t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16258

Published Mar 20, 2020

The bootloader of the homee Brain Cube V2 through 2.23.0 allows attackers with physical access to gain root access by manipulating the U-Boot environment via the CLI after connect…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15654

Published Mar 19, 2020

Comba AC2400 devices are prone to password disclosure via a simple crafted /09/business/upgrade/upcfgAction.php?download=true request to the web management server. The request doe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12127

Published Mar 19, 2020

In ONAP OOM through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12126

Published Mar 19, 2020

In ONAP DCAE through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respectiv…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12125

Published Mar 19, 2020

In ONAP Logging through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respec…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12130

Published Mar 19, 2020

In ONAP CLI through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12129

Published Mar 19, 2020

In ONAP MSB through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12128

Published Mar 19, 2020

In ONAP SO through Dublin, by accessing an applicable port (30234, 30290, 32010, 30270, 30224, 30281, 30254, 30285, and/or 30271), an attacker gains full access to the respective…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-20529

Published Mar 18, 2020

In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12120

Published Mar 18, 2020

An issue was discovered in ONAP VNFSDK through Dublin. By accessing port 8000 of demo-vnfsdk-vnfsdk, an unauthenticated attacker (who already has access to pod-to-pod communicatio…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12119

Published Mar 18, 2020

An issue was discovered in ONAP SDC through Dublin. By accessing port 7000 of demo-sdc-sdc-wfd-fe pod, an unauthenticated attacker (who already has access to pod-to-pod communicat…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 2,226-2,250 of 2,580 CVEsPage 90 of 104