Skip to main content

CWE archive

CWE-552 CVEs

Programmatic archive

483 CVEs tagged with CWE-55244 Critical, 201 High, 225 Medium, 13 Low, 0 Unrated.

CVE-2020-12743

Published May 11, 2020

An issue was discovered in Gazie 7.32. A successful installation does not remove or block (or in any other way prevent use of) its own file /setup/install/setup.php, meaning that…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-12470

Published Apr 29, 2020

MonoX through 5.1.40.5152 allows administrators to execute arbitrary code by modifying an ASPX template.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7306

Published Apr 17, 2020

Byobu Apport hook may disclose sensitive information since it automatically uploads the local user's .screenrc which may contain private hostnames, usernames and passwords. This i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-11469

Published Apr 1, 2020

Zoom Client for Meetings through 4.6.8 on macOS copies runwithroot to a user-writable temporary directory during installation, which allows a local process (with the user's privil…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5289

Published Mar 30, 2020

In Elide before 4.5.14, it is possible for an adversary to "guess and check" the value of a model field they do not have access to assuming they can read at least one other field…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20593

Published Mar 24, 2020

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Gallery leaks Private Mode thumbnails. The Samsung ID is SVE-2019-14208 (July 2019).

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20529

Published Mar 18, 2020

In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5250

Published Mar 5, 2020

In PrestaShop before version 1.7.6.4, when a customer edits their address, they can freely change the id_address in the form, and thus steal someone else's address. It is the same…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10105

Published Mar 5, 2020

An issue was discovered in Zammad 3.0 through 3.2. It returns source code of static resources when submitting an OPTIONS request, rather than a GET request. Disclosure of source c…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4715

Published Feb 17, 2020

The fetch function in OAuth/Curl.php in Dropbox-PHP, as used in ownCloud Server before 6.0.8, 7.x before 7.0.6, and 8.x before 8.0.4 when an external Dropbox storage has been moun…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-3927

Published Feb 3, 2020

An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target sys…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2020-3926

Published Feb 3, 2020

An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target sys…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19843

Published Jan 22, 2020

Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote credential fetch via an unauthenticated HTTP request involving a s…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2019-19018

Published Dec 2, 2019

An issue was discovered in TitanHQ WebTitan before 5.18. It exposes a database configuration file under /include/dbconfig.ini in the web administration interface, revealing what d…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-17221

Published Nov 5, 2019

PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI. The vulnerability exists in the page.open() function of t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17112

Published Oct 9, 2019

An issue was discovered in Zoho ManageEngine DataSecurity Plus before 5.0.1 5012. An exposed service allows a basic user ("Operator" access level) to access the configuration file…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0381

Published Oct 8, 2019

A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2019-17130

Published Oct 4, 2019

vBulletin through 5.5.4 mishandles external URLs within the /core/vb/vurl.php file and the /core/vb/vurl directories.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10829

Published Aug 1, 2019

cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 426-450 of 483 CVEsPage 18 of 20